FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

North Korean WaterPlum Group Compromised 30,000 Devices in 8‑Month Cryptocurrency Theft Campaign

Over an eight‑month period in 2024, the North Korean‑state‑sponsored WaterPlum group compromised roughly 30,000 endpoints across more than 100 countries through a fake‑job‑interview social‑engineering campaign that employed deep‑fake video lures and malicious links to deploy remote‑access trojans, credential stealers, and cryptocurrency‑wallet drainers. The operation yielded an estimated $10.71 million in stolen crypto while overlapping with disclosed zero‑day exploits in Arista VeloCloud Orchestrator (CVSS 10.0), Check Point management servers, and an alleged Oracle PeopleSoft zero‑day linked to ShinyHunters’ FBI breach claim.


LINK COPIED TO CLIPBOARD