WaterPlum (North Korean APT) Global Device Compromise Campaign
First seen Sep 20, 2026 · Updated Sep 20, 2026
A North Korean state-sponsored hacking group known as WaterPlum compromised at least 30,000 devices worldwide between December 2025 and July 2026, stealing over $10.7 million in cryptocurrency. The campaign, detailed in a joint law enforcement advisory, reflects continued DPRK reliance on cybercrime to fund state operations through large-scale device infection and financial theft.
Technical Analysis
WaterPlum's operation appears consistent with prior North Korean campaigns (e.g., TraderTraitor/Lazarus-linked activity) that combine social engineering, trojanized software, and credential/wallet-stealing malware to compromise developer and crypto-related endpoints at scale. The scope of 30,000 infected devices suggests use of supply-chain-adjacent distribution methods such as malicious npm/PyPI packages, fake job-interview coding tests, or trojanized productivity and crypto-wallet tools to achieve broad reach. Stolen credentials and session tokens were likely leveraged to access cryptocurrency exchanges, hot wallets, or CI/CD systems, enabling the transfer of stolen funds to DPRK-controlled infrastructure. Given the pattern of targeting developers and engineers through fake packages and tooling, organizations running AI agents or automated coding/deployment pipelines that pull from public package registries or execute developer-shared code face a real risk of credential exfiltration or agent-tool compromise if infected packages or binaries are inadvertently included in agent workflows.
Affected Systems
Developer workstations, cryptocurrency wallet software, exchange-related infrastructure, and endpoints running compromised software packages or fake job-application tooling; specific OS/software versions not disclosed in source advisory.
Indicators of Compromise
- Not disclosed in available source data; refer to joint law enforcement advisory (FBI/CISA/international partners) for full IOC list including wallet addresses, malware hashes, and C2 domains.
Remediation Steps
- 1
Audit developer and crypto-related endpoints
Scan for known WaterPlum/Lazarus-associated malware signatures and unauthorized software installations, especially on machines with access to crypto wallets or CI/CD credentials.
- 2
Restrict and vet third-party packages
Implement package allow-listing and integrity verification for npm, PyPI, and other registries used by developers or AI agent pipelines to reduce supply-chain infection risk.
- 3
Rotate exposed credentials and API keys
Rotate any credentials, wallet keys, or API tokens potentially exposed on compromised devices, including those used by automated agents or bots.
- 4
Enhance monitoring for crypto transactions
Deploy transaction monitoring and anomaly detection for cryptocurrency wallets and exchange accounts tied to organizational infrastructure.
- 5
Employee awareness training
Train developers and staff to recognize fake job-interview/coding-test lures commonly used by DPRK threat actors to deliver malware.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.