Interestana
Home/News/North Korean WaterPlum Hackers Compromised 30,000 Devices
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

North Korean WaterPlum Hackers Compromised 30,000 Devices

The North Korean hacking group known as WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026, according to a joint law enforcement advisory. This operation resulted in the transfer of over $10.7 million in stolen cryptocurrency to North Korea. The advisory was issued by multiple international agencies, including the U.S. Department of Justice, the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA), alongside counterparts in South Korea, Japan, and the United Kingdom. These agencies detailed the group's modus operandi, which involved the use of sophisticated malware and social engineering tactics to gain unauthorized access to victim systems. WaterPlum's activities are believed to be state-sponsored, aimed at generating revenue for the North Korean regime, which faces extensive international sanctions. The group has been observed deploying various types of malware, including remote access trojans (RATs) and information stealers, to exfiltrate sensitive data and financial credentials. The advisory highlighted that the compromised devices spanned numerous sectors, including finance, technology, and critical infrastructure, posing a significant threat to global cybersecurity. The stolen cryptocurrency was laundered through various illicit channels, including cryptocurrency exchanges and mixers, to obscure its origin and destination. Law enforcement agencies are urging organizations and individuals to enhance their cybersecurity defenses, implement multi-factor authentication, and remain vigilant against phishing attempts and suspicious links. The advisory also provided indicators of compromise (IOCs) and recommended mitigation strategies to help detect and prevent WaterPlum's malicious activities. This operation underscores the persistent threat posed by North Korean state-sponsored hacking groups and their sophisticated methods for evading detection and generating illicit funds. The scale of the compromise, affecting 30,000 devices, indicates a widespread and impactful campaign. The financial gains of $10.7 million represent a substantial contribution to North Korea's illicit funding mechanisms. The collaborative nature of the advisory emphasizes the international effort required to combat such transnational cyber threats. The FBI's involvement, for instance, points to the significant impact on U.S. entities and interests. Similarly, the participation of South Korean and Japanese agencies highlights the regional implications of North Korea's cyber activities. The UK's involvement further underscores the global reach of these operations. The specific timeframe of December 2025 to July 2026 provides a concrete period for the reported compromises, allowing for focused investigation and defense. The advisory's release aims to equip the cybersecurity community with the knowledge and tools to defend against current and future threats from WaterPlum and similar actors. The mention of specific malware types, such as RATs, offers technical details for security professionals. The emphasis on social engineering indicates that human vulnerabilities remain a key target for these attackers. The advisory's call for enhanced defenses and vigilance is a standard but crucial recommendation in the face of such sophisticated threats. The $10.7 million figure is a concrete measure of the financial impact of WaterPlum's campaign. The fact that this money was transferred to North Korea directly links the cyber activity to state-sponsored objectives. The joint nature of the advisory, involving multiple countries, signifies a coordinated international response to a significant cyber threat.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next