← Blog · · df00tech

Joint Advisory: North Korea-Linked WaterPlum Group Tied to 30,000 Device Compromises, $10.7M in Stolen Crypto

security-news campaign

A joint law enforcement advisory attributes a large-scale campaign to the North Korean hacking group known as WaterPlum, reportedly compromising at least 30,000 devices worldwide between December 2025 and July 2026. According to the advisory, the group moved more than $10.7 million in stolen cryptocurrency to North Korea over that period.

Why It Matters

This is a state-sponsored, financially motivated operation rather than opportunistic crime — proceeds are reported to flow directly to North Korea, consistent with the regime's pattern of using cyber theft to fund state activities, including sanctioned programs. A device count in the tens of thousands suggests a broad, non-targeted or widely-cast campaign rather than a narrow, high-value intrusion, meaning organizations of many sizes and sectors could be affected, not just cryptocurrency firms.

What Defenders Should Watch For

  • Unusual outbound connections or beaconing from endpoints to infrastructure associated with North Korean threat actors, particularly where cryptocurrency wallets, exchanges, or hot wallets are present on the network.
  • Unexplained cryptocurrency transfers or wallet activity, especially transactions routed toward mixers or exchanges known to service North Korean-linked actors.
  • Initial-access vectors commonly associated with North Korean groups — phishing with fake job offers or software packages, trojanized applications, and social-engineering approaches targeting developers or finance/crypto personnel — though the advisory as summarized here does not specify the initial access method for this particular campaign.
  • Endpoint compromise indicators consistent with credential theft and remote access tooling, given the scale (30,000+ devices) implied by the report.
  • Monitor for indicators of compromise (IOCs) as they are published by the issuing law enforcement agencies, and cross-reference against any internal cryptocurrency-related infrastructure.

Details on WaterPlum's specific tactics, techniques, and infrastructure were not included in the summary reviewed here, so defenders should treat the above as general hunting angles pending release of the full advisory and associated IOCs.

Developing Story

This item is based on a joint law enforcement advisory as reported and is still developing; specifics on attack vectors, victim sectors, and indicators of compromise may be added as the advisory or follow-on reporting is published. For the original report, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.