INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korean hackers infect thousands of devices across 100 countries

| 2026-10-02 18:33 CRITICAL LOW STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked ransomware group known as Warlock recently targeted multiple sectors, including a water utility, telecom provider, regional government body, and university. The attacks exploited SharePoint vulnerabilities to gain initial access. This incident is part of a broader pattern of cyber activity by the same group, which has also been linked to extortion schemes targeting IT professionals in Japan and other countries. In 2020, cybersecurity firms first identified similar North Korean campaigns targeting job seekers in the defense industry. More recently, Google warned that 250 people working for 10 different news media outlets were targeted by a similar scheme. The WaterPlum campaign is believed to be run through North Korea's General Bureau of the Munitions Industry Department and has been linked to other revenue-generating schemes, including legitimate IT work and cryptocurrency thefts.
Technical Mitigations AI-generated
• Implement regular software updates and patches for SharePoint vulnerabilities to prevent exploitation. • Use two-factor authentication (2FA) or multi-factor authentication (MFA) for job seekers' accounts on social media platforms, gig work websites, and freelance portals to add an extra layer of security against phishing attacks. • Utilize endpoint detection and response (EDR) tools to monitor devices infected with malware strains such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, allowing for swift identification and remediation of compromised systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BeaverTailBeaverTailInvisibleFerretInvisibleFerret
Target & Sectors
FIVE_EYES FIVE_EYES DPRK DPRK DACH DACH cryptocurrencycryptocurrency defensedefense energyenergy governmentgovernment technologytechnology telecommunicationstelecommunications
Incident Timeline
‎between December 2025
Threat actors using the WaterPlum malware infected at least 30,000 devices across 100 countries between December 2025 and July 2026.
general_metric 100 countries
infrastructure 30,000 devices
general_metric 7,000 cryptocurrency wallets
‎July 2026
Threat actors using the WaterPlum malware infected at least 30,000 devices across 100 countries between December 2025 and July 2026.
general_metric 100 countries
infrastructure 30,000 devices
general_metric 7,000 cryptocurrency wallets
‎2026/10/02
North Korean hackers used the WaterPlum campaign to target thousands of devices globally, including those of job applicants in Japan and other countries.
organisation Warlock
organisation IP
organisation Google
organisation Disney
organisation General Bureau
organisation the Munitions Industry Department
financial $12 hackers
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Metrics
financial
12,000,000
Financial Impact / Stolen Funds