North Korean cyber unit WaterPlum hijacks 30,000 devices, siphons $10.7 million in crypto
A joint advisory issued by multiple law‑enforcement agencies warns that the North Korean hacking collective known as WaterPlum has compromised at least 30,000 internet‑connected devices across the globe between December 2025 and July 2026. The campaign, which spanned both consumer and corporate networks, culminated in the transfer of more than $10.7 million in cryptocurrency to accounts linked to the North Korean state.
The advisory, compiled by investigators from several countries, details that WaterPlum leveraged a combination of credential‑stuffing attacks and malicious software implants to gain footholds on vulnerable systems. Once inside, the group deployed crypto‑mining scripts and illicit wallet‑drain tools that quietly redirected digital assets to wallets under North Korean control.
Authorities say the scale of the operation—affecting tens of thousands of devices—marks one of the most extensive cyber‑theft campaigns attributed to a North Korean entity in recent years. While the exact composition of the victim pool remains under review, preliminary analysis points to a mix of home routers, Internet‑of‑Things appliances, and poorly secured corporate endpoints.
WaterPlum’s activities align with a broader pattern of state‑sponsored cyber‑crime that North Korea has pursued to offset international sanctions. The regime has long relied on illicit cyber‑revenue streams, most notably through the Lazarus Group, to fund its nuclear and missile programs. The emergence of WaterPlum suggests a diversification of tactics and possibly a new operational front focused on low‑cost, high‑volume infiltration.
Law‑enforcement officials are urging organizations and private users to audit their networks for unusual cryptocurrency‑related processes, update firmware on IoT devices, and enforce strong, unique passwords. The advisory also recommends deploying endpoint detection tools capable of spotting the specific signatures associated with WaterPlum’s payloads.
Investigators continue to track the flow of the stolen funds, working with cryptocurrency exchanges and blockchain‑analysis firms to trace the money trail. While a portion of the $10.7 million has already been identified moving through mixers and exchange platforms, the full extent of the financial impact remains uncertain. The coordinated response underscores growing international concern over the use of cyber‑theft to finance sanctioned regimes, and signals that further joint operations are likely as authorities seek to disrupt WaterPlum’s infrastructure and prevent future attacks.
Comments (0)
Be the first to comment.
Join the discussion