Act
active
North Korean WaterPlum hackers infected 30K devices, stole $10.7M crypto
- Engineer — Learn: The advisory confirms an active North Korean campaign at scale, but the summary names no specific exploited software or CVEs to patch; review the full law enforcement advisory for any affected platform or dependency details.
- SOC/IR — Plan: Pull the joint law enforcement advisory for WaterPlum IOCs and ATT&CK-mapped TTPs, then build hunts targeting the December 2025–July 2026 activity window across endpoint and network telemetry.
- Leader — Act: A multi-agency advisory on a sustained North Korean campaign affecting 30,000 devices with confirmed financial losses warrants a brief to leadership this week; assess whether your sector or any cryptocurrency-related vendors are in the target profile.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.