North Korean Hackers Breach 30,000 Devices, Seize Over $10 Million in Crypto Assets
Cyber‑security researchers have linked a recent wave of intrusions affecting roughly 30,000 internet‑connected devices to a North Korean state‑backed group known as WaterPlum. The campaign, which unfolded over the past several months, resulted in the theft of an estimated $10.7 million, either directly from cryptocurrency wallets or through the exfiltration of credentials that enabled later transfers.
WaterPlum, which has surfaced in multiple threat‑intel reports, appears to specialize in large‑scale credential harvesting. In this operation, the actors targeted a broad mix of consumer and enterprise hardware, embedding malicious code that allowed remote access and data exfiltration. Security analysts say the scale of the compromise suggests automated scanning and exploitation of common vulnerabilities, a hallmark of financially motivated state actors seeking to fund prohibited programs.
The theft involved access to approximately 7,000 cryptocurrency wallets. Once inside, the attackers either moved funds to exchange‑controlled accounts or siphoned private keys, rendering the original owners unable to recover their assets. While the precise cryptocurrencies involved were not disclosed, the total monetary loss—$10.7 million—places the incident among the larger crypto‑theft events attributed to North Korean groups in recent years.
Experts note that the operation underscores the growing convergence of traditional cyber‑espionage tactics with illicit finance. North Korean cyber units have long been accused of leveraging ransomware, cryptojacking, and direct theft to circumvent international sanctions. The WaterPlum campaign adds to a pattern that includes the notorious Lazarus Group, whose activities have ranged from the 2016 Bangladesh Bank heist to more recent ransomware campaigns.
Authorities and industry watchdogs are urging organizations to review device inventories, apply security patches promptly, and enforce multi‑factor authentication for any crypto‑related services. As investigators continue to trace the flow of the stolen funds, the incident is likely to prompt renewed diplomatic pressure on North Korea and may lead to additional sanctions targeting its cyber‑infrastructure. Meanwhile, the broader cybersecurity community is expected to share indicators of compromise to help mitigate further exploitation of the same vulnerabilities.
Comments (0)
Be the first to comment.
Join the discussion