North Korean WaterPlum Group Compromised 30,000 Devices in 8‑Month Cryptocurrency Theft Campaign
Over an eight‑month period in 2024, the North Korean‑state‑sponsored WaterPlum group compromised roughly 30,000 endpoints across more than 100 countries through a fake‑job‑interview social‑engineering campaign that employed deep‑fake video lures and malicious links to deploy remote‑access trojans, credential stealers, and cryptocurrency‑wallet drainers. The operation yielded an estimated $10.71 million in stolen crypto while overlapping with disclosed zero‑day exploits in Arista VeloCloud Orchestrator (CVSS 10.0), Check Point management servers, and an alleged Oracle PeopleSoft zero‑day linked to ShinyHunters’ FBI breach claim.
- Incident/Breach Overview
- Approximately 30,000 endpoint devices compromised globally.
- Campaign duration ~8 months (early‑late 2024).
-
Estimated cryptocurrency theft: $10.71 million.
-
Attack Vector/Campaign Mechanics
- Fake LinkedIn and recruitment‑site profiles impersonating tech recruiters.
- Deep‑fake video calls used during bogus job interviews to establish trust.
- Malicious links/attachments delivering obfuscated PowerShell and JavaScript downloaders.
- Second‑stage payloads: RATs, credential stealers, clipboard hijackers, malicious browser extensions.
- Use of living‑off‑the‑land binaries (LOLBAS) for persistence and lateral movement.
-
C2 infrastructure: compromised legitimate domains, bullet‑proof hosting, rotating IPs to evade detection.
-
Threat Group Profile/Scale of Impact
- North Korean state‑sponsored WaterPlum APT group.
- Targeted software developers, IT professionals in >100 countries.
- Secondary risks: exposure of source code, internal credential leakage, potential supply‑chain threats.
-
Overlapping cybercrime claims: ShinyHunters FBI breach allegation, Arista VeloCloud zero‑day exploitation, Check Point quiet management‑server attack.
-
Indicators of Compromise (IoCs)/Defensive Actions
- Monitor for anomalous outbound HTTPS to newly registered domains; detect obfuscated PowerShell/JS.
- Block known malicious URLs/IPs cited in OpenVPN, Aviatrix, Paubox, and Japanese Cybersecurity alerts.
- Enforce MFA, restrict execution of unsigned scripts, deploy EDR with LOLBAS detection capabilities.
- Patch Arista VeloCloud Orchestrator (CVE‑2024‑XXXX) and Check Point management servers; apply Oracle PeopleSoft mitigations if relevant.
-
Conduct user‑training on deep‑fake interview scams and verification of recruiter profiles.
-
Conclusion
- WaterPlum illustrates the convergence of state‑sponsored espionage and financially motivated crypto theft via sophisticated social engineering.
- Continuous monitoring, rapid zero‑day patching, and heightened employee awareness are essential defenses.
- Ongoing investigations by the FBI, international CERTs, and vendor security teams remain active.
Related posts
- techjacksolutions.com — North Korean WaterPlum Group Compromised 30,000 Devices in 8-Month Cryptocurrency Theft Campaign
- The Hacker News — Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- news.bitcoin.com — Fake IT Job Interviews Help North Korea Steal Millions in Crypto
- Bingx
- Newsnow
- Sepe
- blog.openvpn.net — ShinyHunters' FBI Claim, VeloCloud CVSS 10.0 & WaterPlum
- Voanews
- The-independent
- Paubox
- Infosecurity-magazine
- Sumsub
- Cyber
- Aviatrix