North Korean WaterPlum hackers infected 30,000 devices worldwide
Overview
A North Korean hacking group known as WaterPlum has reportedly compromised at least 30,000 devices globally between December 2025 and July 2026. The attackers managed to siphon off over $10.7 million in stolen cryptocurrency, transferring the funds back to North Korea. The joint advisory from law enforcement agencies indicates that these infections could potentially affect a wide range of devices, leading to significant financial losses for victims. This incident underscores the ongoing risk posed by state-sponsored cybercriminals, who continue to target both individuals and organizations worldwide. Users and companies alike should remain vigilant and consider enhancing their cybersecurity measures to protect against such sophisticated attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: At least 30,000 devices worldwide
- Action Required: Users should enhance their cybersecurity measures, including regular software updates and monitoring for suspicious activity.
- Timeline: Ongoing since December 2025
Original Article Summary
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
Impact
At least 30,000 devices worldwide
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since December 2025
Remediation
Users should enhance their cybersecurity measures, including regular software updates and monitoring for suspicious activity.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.