North Korean WaterPlum Hackers Infiltrate 30,000 Devices Worldwide

The North Korean group WaterPlum compromised over 30,000 devices worldwide, stealing more than $10.7 million in cryptocurrency between December 2025 and July 2026.

Why it matters

This widespread compromise demonstrates continued risks posed by state-sponsored cybercrime, emphasizing the threat of financial theft through cryptocurrency.

SOC impact

Focus on monitoring for indicators of WaterPlum activity and unusual cryptocurrency-related transactions. Investigate suspicious device behavior and review telemetry correlated with this campaign to identify potential compromises.

Recommended actions

  1. Identify assets potentially impacted by WaterPlum activity
  2. Monitor authentication and network logs for anomalies related to state-sponsored campaigns
  3. Review cryptocurrency transaction telemetry for unauthorized transfers
  4. Investigate alerts tied to known WaterPlum tactics and infrastructure
  5. Collaborate with threat intelligence teams to update detection capabilities

Executive Summary

Between December 2025 and July 2026, the North Korean state-sponsored threat actor WaterPlum compromised over 30,000 devices globally, resulting in the theft of more than $10.7 million in cryptocurrency. A joint law enforcement advisory highlights the scale and financial focus of this campaign, warning organizations to remain vigilant. Operationally, this activity signals a sustained state-backed effort targeting cryptocurrency assets worldwide. Security teams should prioritize detection of related intrusion patterns, validate the presence of affected devices, and scrutinize financial telemetry tied to digital currencies to mitigate ongoing exposure.

SOC Impact

Focus on monitoring for indicators of WaterPlum activity and unusual cryptocurrency-related transactions. Investigate suspicious device behavior and review telemetry correlated with this campaign to identify potential compromises.

Key Areas for SOC Validation

  • Identify assets potentially impacted by WaterPlum activity
  • Monitor authentication and network logs for anomalies related to state-sponsored campaigns
  • Review cryptocurrency transaction telemetry for unauthorized transfers
  • Investigate alerts tied to known WaterPlum tactics and infrastructure
  • Collaborate with threat intelligence teams to update detection capabilities

Why It Matters

This widespread compromise demonstrates continued risks posed by state-sponsored cybercrime, emphasizing the threat of financial theft through cryptocurrency.

Source