INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
North Korean hackers infect thousands of devices across 100 countries
| 2026-10-02 18:33 CRITICAL LOW STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked ransomware group known as Warlock recently targeted multiple sectors, including a water utility, telecom provider, regional government body, and university. The attacks exploited SharePoint vulnerabilities to gain initial access. This incident is part of a broader pattern of cyber activity by the same group, which has also been linked to extortion schemes targeting IT professionals in Japan and other countries. In 2020, cybersecurity firms first identified similar North Korean campaigns targeting job seekers in the defense industry. More recently, Google warned that 250 people working for 10 different news media outlets were targeted by a similar scheme. The WaterPlum campaign is believed to be run through North Korea's General Bureau of the Munitions Industry Department and has been linked to other revenue-generating schemes, including legitimate IT work and cryptocurrency thefts.
Technical Mitigations AI-generated
• Implement regular software updates and patches for SharePoint vulnerabilities to prevent exploitation.
• Use two-factor authentication (2FA) or multi-factor authentication (MFA) for job seekers' accounts on social media platforms, gig work websites, and freelance portals to add an extra layer of security against phishing attacks.
• Utilize endpoint detection and response (EDR) tools to monitor devices infected with malware strains such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, allowing for swift identification and remediation of compromised systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BeaverTailBeaverTailInvisibleFerretInvisibleFerret
Target & Sectors
FIVE_EYES
FIVE_EYES
DPRK
DPRK
DACH
DACH
cryptocurrencycryptocurrency
defensedefense
energyenergy
governmentgovernment
technologytechnology
telecommunicationstelecommunications
Incident Timeline
between December 2025
Threat actors using the WaterPlum malware infected at least 30,000 devices across 100 countries between December 2025 and July 2026.
Click on any entity below to view its context and source!
general_metric
100 countries
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
infrastructure
30,000 devices
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
general_metric
7,000 cryptocurrency wallets
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
July 2026
Threat actors using the WaterPlum malware infected at least 30,000 devices across 100 countries between December 2025 and July 2026.
Click on any entity below to view its context and source!
general_metric
100 countries
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
infrastructure
30,000 devices
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
general_metric
7,000 cryptocurrency wallets
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
2026/10/02
North Korean hackers used the WaterPlum campaign to target thousands of devices globally, including those of job applicants in Japan and other countries.
Click on any entity below to view its context and source!
organisation
Warlock
The China-linked ransomware group Warlock targeted a water u....
organisation
IP
The report notes that WaterPlum actors and North Korean IT workers used the same IP addresses when accessing laptop farms or applying for positions at Japanese cryptocurrency companies.
organisation
Google
Dating back to 2020, cybersecurity firms have identified similar North Korean campaigns targeting job seekers in the
defense industry
, and Google
warned in 2022
that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted with malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
organisation
Disney
Dating back to 2020, cybersecurity firms have identified similar North Korean campaigns targeting job seekers in the
defense industry
, and Google
warned in 2022
that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted with malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
organisation
General Bureau
The report said the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department — which is within the Central Committee of the Workers Party of Korea.
organisation
the Munitions Industry Department
The report said the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department — which is within the Central Committee of the Workers Party of Korea.
financial
$12 hackers
In April, incident responders
uncovered a similar campaign
involving the same strains of malware where hackers stole up to $12 million in cryptocurrency through malware attacks on personal devices.
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Click for context!
The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets.
Metrics
financial
12,000,000
Financial Impact / Stolen Funds
In April, incident responders
uncovered a similar campaign
involving the same strains of malware where hackers stole up to $12 million in cryptocurrency through malware attacks on personal devices.
Intelligence Sources
TheRecord
2026-09-18
Mastodon BleepingComputer
2026-10-02
The China-linked ransomware group Warlock targeted a water u...
Mastodon BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T23:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
organisation
Identified Entity
Warlock
entity
7x
attribution
Attributing Entity
FBI
authority
4x
industry
Targeted Sector
Government
sector
4x
target region
Target Country
Japan
country
4x
timeline
Temporal Reference
2020
date
2x
source region
Origin Country
China
country
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
target region
Target Region
DPRK
region
2x
malware
Malware Payload
BeaverTail
tool
Contextual Telemetry
Context Block
7 METRICS
source region
Origin Region
DPRK
region
general metric
People
250
people
general metric
Different News Media
10
different news media
general metric
Countries
100
countries
infrastructure
Devices
30,000
devices
general metric
Cryptocurrency Wallets
7,000
cryptocurrency wallets
financial
Financial Impact / Stolen Funds
12,000,000
hackers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.