Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

North Korean ‘WaterPlum’ Campaign Infects 30,000 Devices Across 100 Countries, Steals Crypto from Job Seekers

North Korean actors behind the WaterPlum campaign have compromised at least 30,000 devices in 100 countries by luring job seekers into downloading malicious files. The malware exfiltrates cryptocurrency wallet credentials and can be leveraged for later corporate infiltration, highlighting supply‑chain and credential‑theft risks for organizations hiring remote talent.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

North Korean ‘WaterPlum’ Campaign Infects 30,000 Devices Across 100 Countries, Steals Crypto from Job Seekers

What Happened — North Korean actors operating the “WaterPlum” campaign compromised at least 30,000 devices in 100 nations by posing as recruiters on social‑media, gig‑work, and freelance portals. Victims were tricked into downloading malicious files that installed infostealer and remote‑management tools, allowing theft of cryptocurrency‑wallet credentials and persistent access to the devices.

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous third‑party risk monitoring and verifiable onboarding controls to prevent supply‑chain compromise.
  • Demonstrates why organizations must maintain auditable evidence of device hygiene and credential‑management for all external hires.
  • Underlines the importance of endpoint detection and response (EDR) logs as defensible proof of control effectiveness.

Who Is Affected – Technology firms hiring remote engineers, cryptocurrency companies, recruitment platforms, and any organization that onboards external talent.

Recommended Actions – Verify candidate identities before granting network access, enforce endpoint security baselines on all devices used for work, and map supply‑chain risk controls to your audit framework with continuous evidence collection. Source: The Record

Technical Notes – Attack vector: social‑engineering (phishing) via fake recruiter messages; malware families include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle; primary data stolen: cryptocurrency‑wallet credentials and personal identifiers. Source: same as above

📰 Original Source
https://therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →