North Korean Hackers Compromised 30,000 Devices
A global malware campaign spanning 2025 and 2026 targeted thousands of crypto wallets to fund military activities.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust that current remote hiring processes effectively verify the identity of all job applicants?
Between December 2025 and July 2026, the North Korean hacking group WaterPlum compromised at least 30,000 devices across 100 countries. This operation, detailed in an international security advisory, resulted in the theft of $10.7 million in cryptocurrency.
Why it matters
The campaign highlights the use of advanced social engineering and AI tools to facilitate illicit financial flows that sustain North Korean military programs. By infiltrating professional networks, the group leveraged stolen identities to bypass standard corporate security protocols.
WaterPlum drained more than 7,000 cryptocurrency wallets during the campaign. This volume of theft represents a significant scale of operations compared to prior documented campaigns by the state-linked 313 General Bureau.
The players
WaterPlum
A North Korean hacking group known for utilizing advanced malware and AI-based social engineering to target tech and crypto sectors.
313 General Bureau
The North Korean state-affiliated entity reportedly managing the infrastructure and strategic direction of these cyber operations.
The details
The group deployed a mix of JavaScript loaders, Python backdoors, and information-stealing trojans to maintain persistent access to victim systems. During sham hiring processes for AI and crypto firms, operators utilized AI-powered face-swapping tools in video interviews to mimic legitimate recruiters. Once trust was established, victims were prompted to install malware disguised as coding tests or video-conferencing software, which then enabled identity theft and credential harvesting.
Timeline
December 2025 to July 2026: WaterPlum compromised 30,000 devices globally.
Mid-September 2026: International agencies published the joint security advisory regarding the campaign.
The Tech Race
This campaign follows a pattern of state-sponsored cyber espionage established by the North Korean 313 General Bureau. It marks a departure from traditional phishing by integrating real-time AI impersonation to subvert corporate trust models.
Professional organizations and tech workers should maintain heightened scrutiny of unsolicited recruitment offers for roles in AI, crypto, or NFT companies. Security teams should monitor for the use of unauthorized remote access software or unusual Python-based execution patterns on employee devices.
The takeaway
The sophisticated use of AI-based impersonation in hiring processes demonstrates that standard verification methods are increasingly vulnerable to state-sponsored actors. Stakeholders should track future joint security advisories from international agencies for updated indicators of compromise related to these specific malware strains.
Further reading
For more context on how state-linked actors target modern digital infrastructure, explore the Cybersecurity section.
Live Poll
Do you trust that current remote hiring processes effectively verify the identity of all job applicants?






