ZeroHour
Threat actor

North Korea

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Nations take action on North Korean IT workers after UN report

Multiple countries took legal action against North Korean IT worker facilitators following a new UN-linked MSMT report on the illicit scheme.

The US-led Multilateral Sanctions Monitoring Team released a report detailing global legal responses to North Korea's illicit IT worker scheme, which uses stolen or purchased identities to place workers in high-paying IT jobs. Argentina opened an investigation and froze assets of alleged money launderer Antonia Doroganova, while Pakistan opened a case against alleged forger Syeda Aliya Batool Zaidi and two facilitators. Vietnam and Laos also took steps including sanctions and investigations, and China has increased surveillance, arresting one IT worker for allegedly stealing military secrets. North Korean workers abroad generated up to $800 million last year, and at least 17 countries still host roughly 100,000 North Korean workers.

The Recordupdated · 4h agofirst · 6h agoPolicy & legal 3 sources

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

FBI and Japanese police advisory ties North Korea's WaterPlum campaign to $10.5M stolen from job seekers via fake-recruiter malware on 30,000 devices.

A joint advisory from the FBI, US Defense Department, Japan's National Police Agency and partners describes 'WaterPlum', North Korean cyber actors posing as AI and blockchain companies to recruit job seekers. Between December 2025 and July 2026 the group infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets, totaling over $10.5 million. Victims, mostly web designers, engineers and crypto specialists in Japan and elsewhere, were contacted via social media and freelance portals and told to download files during interviews, leading to infection with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware plus remote management tools. The campaign is intertwined with DPRK IT-worker laptop-farm schemes and is attributed to North Korea's General Bureau of the Munitions Industry Department; Japanese police disrupted a laptop farm for the first time.

The Recordupdated · 4h agofirst · 16h agoThreat actor in the wild 3 sources