Authorities in Australia, Germany, Japan and the US say a North Korean hacking group known as WaterPlum has compromised over 30,000 devices and 7,000 crypto wallets by posing as recruiters and sending malware-laced coding tests to tech workers. The scheme has netted at least $10.71 million in cryptocurrency, funneled back to North Korea.
techspot.com
· 2026-09-21
Cybersecurity agencies from Japan, the US, Australia and Germany issued a joint advisory identifying North Korea's WaterPlum group as the actor behind malware hidden in fake job application coding tests. The scheme has infected over 30,000 devices across 100 countries and compromised more than 7,000 crypto wallets, netting $10.71 million believed to fund the North Korean government.
tomshardware.com
· 2026-09-20
A joint advisory from law enforcement in Japan, the US, Australia and Germany says the North Korean-linked group WaterPlum infected over 30,000 devices across more than 100 countries between December 2025 and July 2026. The hackers drained more than 7,000 cryptocurrency wallets and moved over $10.7 million worth of crypto assets to North Korea, using fake job interviews and malicious code disguised as coding tests or software projects to infect victims.
bleepingcomputer.com
· 2026-09-19
Researchers monitoring the area around North Korea's underground nuclear testing site have logged 1,399 local earthquakes since the country began detonating nuclear devices there. Scientists say this rate of seismic activity is unprecedented for the region compared to historical records.
gizmodo.com
· 2026-09-17
Rapid7 reports that a stealthy espionage campaign has compromised South Korean automotive and media companies since early 2025, with medium-confidence attribution to North Korean APT37 based on overlapping command-and-control infrastructure. The attackers exploited the open-source HAProxy load balancer to install a custom Linux toolkit called TED, granting them visibility into and control over victims' network traffic.
darkreading.com
· 2026-09-16