North Korean WaterPlum Hackers Launch Global Cyberattack, Infect 30,000 Devices
North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide
Attack Overview
A cyber operation attributed to North Korean actors known as WaterPlum compromised approximately 30,000 devices globally between September 2025 and May 2026. The attack leveraged compromised developer tools and software packages to infiltrate systems across multiple regions, highlighting vulnerabilities in software supply chains and the growing threat of targeted development environments.
Tactics and Techniques
Malicious Methods
The campaign involved a multi-year strategy that exploited trusted developer platforms and workflows. Attackers focused on software developers, using their compromised environments as a gateway to access broader networks. Researchers in Japan, Australia, and Germany collaborated to analyze the activity, underscoring the international scale of the breach.
Social Engineering
WaterPlum employed multiple tactics to compromise developers, including injecting malicious JavaScript into npm packages, exploiting compromised developer tools, and utilizing supply-chain techniques. Social engineering played a critical role, with attackers impersonating recruiters to lure developers into engaging with malicious files or code.
Supply-Chain Risks
This approach allowed adversaries to infiltrate development ecosystems, gaining access to source code, sensitive resources, and additional systems. The operation deployed a range of malicious tools designed for different attack phases. These included initial access malware, data exfiltration tools, and mechanisms for maintaining persistence on compromised systems.
WaterPlum’s Connection
Attackers also embedded harmful code within legitimate software packages and workflows, making detection challenging. This method capitalizes on the trust placed in development environments, enabling stealthy infiltration. Supply-chain attacks pose significant risks due to their ability to propagate beyond the initial target.
Government Warnings
Japanese authorities, including the National Police Agency, issued warnings about the dangers of North Korean IT workers. The advisory highlighted risks such as remote positions granting access to corporate systems and emphasized the need for rigorous verification of recruitment details, identities, and employment credentials.
Implications for Cybersecurity
The WaterPlum campaign underscores the expanding reach of attacks targeting developers. By exploiting vulnerabilities in software supply chains, adversaries can compromise a large number of systems through a single breach. The incident has intensified focus on the security of development tools, third-party packages, and remote access arrangements.
Conclusion
Organizations must now scrutinize not only their own networks but also the broader ecosystem of dependencies that support their operations. The campaign highlights a critical shift in cyber threat landscapes, where developers and their tools have become prime targets. Attackers no longer need to directly breach organizations; instead, they can exploit weaknesses in development processes to gain access to larger systems. This necessitates a reevaluation of security strategies, emphasizing verification of remote hires, control over sensitive development environments, and rigorous assessment of software dependencies to prevent widespread compromise.
