North Korean Group Compromises 30,000 Devices in Global Cyber Campaign
A massive cyber campaign linked to North Korea's WaterPlum group has compromised over 30,000 devices across more than 100 countries. The campaign, which took place between December 2025 and July 2026, targeted software developers, web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 through fraudulent employment opportunities.
WaterPlum actors impersonated legitimate AI, cryptocurrency, and NFT companies, approaching potential victims through recruitment, social-media, freelance, and employment platforms. During purported interviews or coding tests, victims were instructed to download projects, execute code, or troubleshoot technical problems, which delivered malware enabling persistent remote access and the extraction of credentials, browser data, keystrokes, screenshots, identity documents, and cryptocurrency-wallet information.
The campaign is part of a broader North Korean cyber ecosystem where financially motivated operations, espionage, and the exploitation of legitimate digital services increasingly overlap. The authorities' findings indicate that stolen credentials and identity documents can support further impersonation, while access obtained through compromised developers may facilitate attacks against their employers, clients, or contracting partners.