North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices

North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.
Table of Contents
    Add a header to begin generating the table of contents

    North Korean hacking group WaterPlum compromised at least 30,000 devices globally and transferred more than $10.7 million in stolen cryptocurrency to North Korea during an eight-month campaign that ran from December 2025 through July. Law enforcement agencies disclosed the operation in a joint advisory released in September, providing indicators of compromise to help organizations detect WaterPlum infections.

    WaterPlum Campaign Timeline and Scope

    The WaterPlum campaign began in December 2025 and continued through at least July. During this eight-month window, attackers infected a minimum of 30,000 devices across multiple countries. The joint law enforcement advisory does not specify which countries were most heavily targeted, but the geographic spread indicates a global campaign rather than a regionally focused operation.

    The stolen cryptocurrency — totaling more than $10.7 million — has been traced to wallets controlled by North Korea. Cryptocurrency theft is a strategic priority for the North Korean regime because it provides untraceable hard currency that can fund weapons programs, bypass international sanctions, and support state operations without relying on the formal banking system.

    How WaterPlum Infections Lead to Cryptocurrency Theft

    WaterPlum’s technical capabilities are not detailed in the joint advisory, but the campaign’s outcome — large-scale cryptocurrency theft from 30,000 compromised devices — suggests the malware targets cryptocurrency wallets, exchanges, or applications that manage digital assets.

    Typical cryptocurrency theft malware operates by stealing private keys, capturing wallet credentials, monitoring clipboard activity to redirect cryptocurrency transactions, or exfiltrating seed phrases that allow attackers to reconstruct a victim’s wallet on another device. Once attackers gain control of a victim’s cryptocurrency holdings, they can transfer funds to their own wallets, often using mixing services or privacy coins to obscure the trail.

    The fact that law enforcement traced the stolen funds to North Korean-controlled wallets indicates that at least some of the laundering steps failed or were skipped. In many cryptocurrency theft campaigns, attribution is difficult because attackers use sophisticated laundering techniques to break the transaction chain. The ability to link the stolen $10.7 million directly to North Korea suggests either that WaterPlum did not prioritize laundering or that law enforcement has developed new methods to trace cryptocurrency flows even after mixing.

    The 30,000-Device Footprint and Target Profile

    WaterPlum’s infection of 30,000 devices is significant. This footprint suggests broad targeting rather than a narrow focus on high-value individuals or organizations. While some nation-state campaigns prioritize depth — thoroughly compromising a small number of strategically important targets — WaterPlum appears to have prioritized breadth, infecting as many devices as possible to maximize cryptocurrency theft opportunities.

    The victim profile likely includes both consumers and enterprises. Consumer devices often hold cryptocurrency wallets for personal investment, while enterprise devices may manage wallets for business operations, payroll, or treasury functions. Attackers targeting this many devices would typically use automated distribution mechanisms such as malicious software bundles, phishing campaigns, or exploitation of vulnerabilities in widely used applications.

    Law Enforcement Advisory Provides Indicators of Compromise

    The joint law enforcement advisory includes indicators of compromise that organizations and individuals can use to detect WaterPlum infections. These indicators typically include file hashes, registry keys, network traffic patterns, or command-and-control domains associated with the malware.

    Organizations should compare their security logs and endpoint detection data against the published indicators. If a match is found, the affected device should be isolated from the network immediately to prevent further data exfiltration or lateral movement. Cryptocurrency wallet credentials stored on or accessed from the infected device should be considered compromised, and funds should be transferred to new wallets with fresh credentials.

    Cryptocurrency Theft Funds North Korean State Priorities

    North Korea’s sustained focus on cryptocurrency theft reflects the regime’s need for hard currency in the face of international sanctions. Traditional revenue sources such as exports, foreign investment, and banking relationships are restricted by sanctions regimes imposed by the United Nations, the United States, and other countries.

    Cryptocurrency offers an alternative. It can be stolen remotely without requiring physical access to banks or payment systems, and it can be transferred across borders without passing through the correspondent banking networks that enforce sanctions compliance. Once stolen, cryptocurrency can be converted to fiat currency through exchanges in jurisdictions with weak anti-money laundering controls or used directly to purchase goods and services.

    WaterPlum in the Context of North Korean Cyber Operations

    WaterPlum is one of several North Korean hacking groups engaged in cryptocurrency theft. Other groups in the same ecosystem have targeted cryptocurrency exchanges, decentralized finance platforms, and individual wallet holders. The cumulative impact of these operations is measured in billions of dollars over the past several years.

    The WaterPlum campaign’s eight-month duration and 30,000-device scale indicate a mature operation with established infrastructure. The group likely maintains command-and-control servers, malware distribution channels, and laundering pipelines that allow it to operate continuously without frequent retooling.

    Response Guidance for Organizations and Individuals

    Organizations and individuals should review the indicators of compromise in the joint law enforcement advisory and scan their environments for signs of WaterPlum activity. This includes checking for the presence of malicious files, reviewing network logs for connections to known command-and-control infrastructure, and auditing cryptocurrency wallet activity for unauthorized transactions.

    For users who hold cryptocurrency, best practices include storing wallet credentials offline in hardware wallets or air-gapped systems, enabling multi-factor authentication on exchange accounts, and monitoring wallet activity for unexpected transfers. Users who detect unauthorized access to their wallets should report the incident to law enforcement and the relevant cryptocurrency exchange or wallet provider.

    The WaterPlum disclosure demonstrates the ongoing threat that nation-state actors pose to cryptocurrency holders. As long as cryptocurrency theft remains a viable funding source for sanctioned regimes, campaigns like WaterPlum will continue. Defenders must assume that sophisticated attackers will target their cryptocurrency holdings and implement layered security controls to reduce the risk of successful theft.

    Related Posts