Law enforcement agencies have issued a joint advisory detailing a sustained campaign by the North Korean hacking group WaterPlum, which compromised at least 30,000 devices worldwide and stole over $10.7 million in cryptocurrency between December 2025 and July 2026.
The coordinated attack represents a significant cyber operation attributed to North Korea's state-sponsored hacking infrastructure. According to the advisory, WaterPlum systematically infected devices across multiple countries over an eight-month period, establishing persistent access to networks and systems.
The hackers successfully siphoned more than $10.7 million in cryptocurrency, transferring the stolen digital assets to North Korea. This theft underscores the evolving tactics of state-sponsored threat actors who increasingly target financial assets and cryptocurrency holdings rather than traditional intellectual property or classified information.
The scale of the operation—affecting 30,000 devices—indicates a widespread infection vector, potentially through compromised software, malicious downloads, or phishing campaigns. The extended timeframe suggests WaterPlum maintained operational capability without detection for months, highlighting gaps in security monitoring and threat detection across affected organizations.
WaterPlum joins a roster of known North Korean hacking groups linked to state interests, including Lazarus Group and other units operating under Kim Jong-un's regime. These organizations have previously targeted financial institutions, cryptocurrency exchanges, and entertainment companies.
Law enforcement agencies coordinating the advisory recommend immediate security audits, credential changes, and network monitoring for signs of compromise. Organizations are advised to patch systems, disable suspicious accounts, and implement enhanced detection mechanisms for unauthorized access.
The advisory signals increased international focus on North Korean cyber operations, which generate significant revenue for the isolated nation under international sanctions. As cryptocurrency theft has become a primary funding mechanism, security agencies continue strengthening defenses against these state-backed actors.
Victims of the WaterPlum campaign should report incidents to relevant law enforcement and cyber authorities to support ongoing investigation and attribution efforts.
A proof-of-concept attack called BragJack can hijack AI assistants across multiple browsers and platforms through a single malicious extension. Security researcher Gal Weizman from Forever Security demonstrated the vulnerability using a Prompt Forcing technique.
If your PC is running slowly or behaving unusually, malware may be the culprit. Running a malware check is a straightforward way to diagnose and address the problem.
A detailed investigation revealed that smart TVs from major manufacturers collect extensive user data, including audio recordings and viewing habits, even when devices appear powered off. The practice extends across the industry, not limited to LG.