North Korean WaterPlum hackers infected 30,000 devices worldwide
Recorded: Sept. 19, 2026, 2 p.m.
| Original | Summarized |
North Korean WaterPlum hackers infected 30,000 devices worldwide News Featured OpenAI details more cases of AI agents taking unauthorized actions Brevo supply-chain attack injected ClickFix scripts on customer sites Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues North Korean WaterPlum hackers infected 30,000 devices worldwide ShinyHunters hacks Clop leak site, threatens to extort ransomware gang Get 25 hours of ChatGPT & AI training for just $19.99 Calling viral AI actress Tilly Norwood? Agree to a face scan first Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityNorth Korean WaterPlum hackers infected 30,000 devices worldwide North Korean WaterPlum hackers infected 30,000 devices worldwide By Bill Toulas September 19, 2026 A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. Source: FBI Source: FBI Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Crypto theft Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories Windows 11 KB5124008 update breaks domain trust for some users Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues Sponsor Posts Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report. Automate Onboarding and Access Reviews with No-Code IGA: See how it works Patch automation needs more than speed. Action1 brings control into every stage of deployment. Watch a working exploit hit live controls and see exactly what blocks, detects, or misses Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
A joint law enforcement advisory from Japanese, US, Australian, and German authorities warns that the North Korean hacking group WaterPlum compromised a minimum of 30,000 devices across more than 100 countries between December 2025 and July 2026, exfiltrating over $10.7 million in cryptocurrency to North Korea. This activity is linked to a multi-year campaign termed "Contagious Interview," which targets job seekers by impersonating legitimate entities such as AI, cryptocurrency, or NFT companies, or by utilizing recruiting and freelance platforms. The attackers manipulate victims during fake interviews and coding tests, instructing them to download projects, resolve supposed video-conferencing issues, or execute malicious code to gain access. The WaterPlum actors operate within a broader ecosystem of North Korean threat actors engaged in financially motivated attacks aimed at funding the regime's weapons programs. The advisory specifies several malware families associated with these operations, including BeaverTail, a JavaScript malware concealed within npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie, a JavaScript remote-access trojan and information stealer; OtterCandy, which is a composite malware combining OtterCookie and Remote Access Trojan capabilities; and StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects that executes code upon folder opening. Once a device is compromised, the attackers execute tactics to steal sensitive data, including browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, in addition to capturing screenshots. Furthermore, they leverage these infected computers to pivot into the networks of employers or clients, enabling attacks focused on intellectual property theft and espionage. The advisory further indicates a direct connection between WaterPlum actors and North Korean IT worker operations, noting that some hackers function as remote IT workers performing web development for clients, often utilizing the same IP addresses. Investigators also found evidence that North Korean IT workers reuse stolen identity documents obtained through WaterPlum attacks to impersonate victims and secure employment. The advisory further connects WaterPlum to North Korea's weapons research and production infrastructure, noting that the actors and some IT workers operate under the Munitions Industry Department, specifically the 313 General Bureau. Japan's National Police Agency recently dismantled a North Korean IT-worker laptop farm, confirming transfers of hundreds of millions of yen abroad through this channel. Consequently, the advisory strongly warns that organizations must rigorously verify the identities, locations, and qualifications of job applicants, restrict their access to only the systems and data strictly necessary for their roles, and encourage developers to avoid executing unknown code outside secure sandboxes while closely inspecting provided files and code for additional payloads. |