← All posts· Incident Response

North Korean Hackers and the WaterPlum Campaign: Lessons in Incident Response

September 21, 2026

Recent advisories from global law enforcement detail the "WaterPlum" campaign, where North Korean state-sponsored actors leverage sophisticated social engineering to target job applicants, leading to widespread device infection and cryptocurrency theft. This incident underscores the critical need for robust incident response planning and employee cybersecurity awareness.

Recent advisories from global law enforcement detail the "WaterPlum" campaign, where North Korean state-sponsored actors are leveraging sophisticated social engineering to target job applicants, leading to widespread device infection and cryptocurrency theft. This incident, impacting thousands of devices across numerous countries, highlights persistent threats from state-sponsored groups and the critical need for robust incident response planning and continuous employee cybersecurity awareness.

Understanding the WaterPlum Campaign

The "WaterPlum" campaign involves state-sponsored cyber actors, specifically from North Korea, who have successfully compromised thousands of devices across 100 countries. These attackers employ a deceptive tactic: they pose as representatives from legitimate-sounding AI or blockchain companies to lure unsuspecting job applicants. Once trust is established, the attackers distribute malicious software, leading to device infection and, ultimately, the theft of cryptocurrency.

This broad campaign was brought to light through a joint advisory issued by the FBI and Defense Department, working alongside international partners such as Japan's National Police Agency and law enforcement agencies in Australia and Germany, as reported by The Record. Such international cooperation underscores the global nature of these sophisticated cyber threats.

The Attack Vector: Deception and Social Engineering

The primary attack vector for WaterPlum is sophisticated social engineering. The attackers exploit the job search process, a time when individuals are often eager and less guarded. By masquerading as recruiters or hiring managers from attractive, cutting-edge companies, they bypass initial skepticism.

"The human element remains the most persistent vulnerability in cybersecurity. Even the most advanced technical defenses can be circumvented by a well-executed social engineering attack."

The malicious payload is then delivered, often disguised as a legitimate application, coding test, or project file. Once executed, it grants the attackers unauthorized access to the victim's device and, subsequently, their cryptocurrency assets. This method capitalizes on trust and a lack of specific cybersecurity awareness and phishing training related to job application scams.

Business Impact and Broader Implications

The direct impact on individuals affected by WaterPlum is significant, primarily involving the theft of their cryptocurrency. However, the campaign also carries broader implications for organizations. If an employee, contractor, or job applicant uses a company-issued device or network during such a scam, the organization itself can be compromised. This could lead to:

  • Data Breach: Exposure of sensitive company data or intellectual property.
  • Network Compromise: Attackers gaining a foothold within the corporate network, enabling further lateral movement.
  • Reputational Damage: Loss of customer trust and public standing if the organization is linked to a breach.
  • Financial Loss: Direct costs associated with incident response, legal fees, regulatory fines, and business disruption.

Beyond direct financial theft, the presence of state-sponsored actors signifies a higher level of threat sophistication and persistence. Organizations must recognize that these groups often aim for more than just immediate financial gain; they may seek long-term espionage or disruption, necessitating a robust cybersecurity strategy and consulting approach.

Lessons Learned from WaterPlum

The WaterPlum campaign offers several critical lessons for organizations striving to enhance their security posture.

Prioritize Cybersecurity Awareness Training

Employees are often the first and last line of defense. Regular, engaging cybersecurity awareness and phishing training is paramount. This training should specifically address social engineering tactics, including sophisticated phishing attempts disguised as job offers or recruitment communications. Simulated phishing exercises can help reinforce these lessons and identify vulnerable employees.

Implement Robust Endpoint Security

Comprehensive endpoint protection is non-negotiable. This includes next-generation antivirus, Endpoint Detection and Response (EDR) solutions, and strict application whitelisting. These tools can detect and block malicious software even if it manages to bypass initial email filters. Proactive measures such as vulnerability assessments also help identify and patch weaknesses in endpoints before they can be exploited.

Strengthen Access Controls

Even if a device is compromised, strong access controls can limit the damage. Implementing the principle of least privilege, multi-factor authentication (MFA) everywhere, and Privileged Access Management (PAM) helps ensure that attackers cannot easily move laterally or access critical systems even after gaining initial access.

Develop and Test an Incident Response Plan

No organization is immune to cyberattacks. A well-defined and regularly tested incident response plan is crucial. This plan should outline clear steps for detection, containment, eradication, recovery, and post-incident analysis. Organizations should know exactly who does what when an incident occurs, minimizing response times and reducing potential damage.

Leverage Threat Intelligence

Staying informed about emerging threats, such as the WaterPlum campaign, is vital. Utilizing managed threat intelligence services can provide early warnings about tactics, techniques, and procedures (TTPs) used by threat actors, allowing organizations to proactively adjust their defenses.

How Lyra Helps

Lyra provides comprehensive Incident Response & Recovery services designed to help organizations prepare for, respond to, and recover from sophisticated cyberattacks like WaterPlum. Our expert team works proactively to establish a resilient security posture and react decisively when an incident occurs.

We assist with developing robust incident response plans, conducting simulations to test their effectiveness, and deploying advanced security technologies like Endpoint Detection and Response (EDR) and Managed Detection and Response (MDR) for 24/7 threat monitoring and active response. In the event of a breach, Lyra’s rapid response capabilities focus on containing the threat, eradicating malicious presence, and restoring normal operations with minimal disruption.

Our approach minimizes the impact of attacks, ensures business continuity, and helps organizations navigate the complex landscape of post-incident recovery, including forensic analysis and strengthening defenses against future threats. For more details on how we protect your business, explore our full range of solutions.

Next Steps for Enhanced Security

Protecting your organization from state-sponsored threats and sophisticated social engineering requires a proactive and multi-layered security strategy. Review your current security posture, invest in comprehensive employee training, and ensure your incident response capabilities are robust.

If you are concerned about your organization's ability to defend against advanced cyber threats or recover from a breach, Lyra is here to help. Contact Lyra today to discuss your specific needs and learn how our tailored cybersecurity solutions can safeguard your business.

incident-responsecybersecurity-awarenesssocial-engineeringstate-sponsored-threatsthreat-intelligence

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.