A joint law enforcement advisory has exposed a major campaign by North Korean-linked hackers, dubbed WaterPlum, compromising over 30,000 devices worldwide between December 2025 and July 2026. The group exfiltrated at least $10.7 million in cryptocurrency, with the true total likely higher due to the use of sophisticated laundering techniques.
According to a report by BleepingComputer, the campaign signifies a strategic shift in state-sponsored financial cybercrime. Moving away from targeting high-profile cryptocurrency exchanges, WaterPlum adopted a high-volume "spray and pray" approach, harvesting smaller amounts from a vast, distributed network of victims including decentralized finance (DeFi) protocols and individual wallets.
The operation's key innovation was its sophisticated abuse of software supply chains. The group focused on poisoning open-source repositories and hijacking legitimate software update mechanisms to distribute malware. This method enabled massive scale with minimal direct interaction, turning trusted development infrastructure into a primary initial access vector.
The hackers initially gained a foothold by exploiting vulnerable edge devices such as routers and firewalls. They then deployed common, legitimate administrative tools for command-and-control (C2) activities. This "living off the land" tactic helps malicious traffic blend with normal network operations, making detection significantly more challenging for security teams.
The $10.7 million figure cited in the advisory is widely considered a conservative baseline. The use of cryptocurrency mixers and cross-chain bridges to obscure the funds' trail means the aggregate financial impact is substantially greater. This pattern of obfuscation underscores the persistent challenge in tracing state-sponsored theft.
For Hong Kong, a major fintech and virtual asset hub, this development carries immediate relevance. The city's expanding digital asset ecosystem presents a lucrative target for groups employing these distributed, supply chain-focused attacks. Defenders should note that the threat does not require sophisticated zero-day exploits but rather preys on common weaknesses in software dependency management and network device hygiene.
The advisory outlines critical defensive actions organizations must take. These include rigorously verifying software dependencies and update sources, monitoring for anomalous behavior on edge devices, and auditing the use of common system administration tools. Implementing network segmentation and a zero-trust architecture can also limit the blast radius of a successful compromise.
The WaterPlum campaign underscores how trust in open-source ecosystems and standard IT tools can be weaponized. As attackers evolve from direct heists to systemic supply chain poisoning, defensive strategies must similarly evolve to scrutinize the integrity of the entire software lifecycle.
一項聯合執法部門公告揭露,一個與朝鮮有關、代號「WaterPlum」的黑客組織,於2025年12月至2026年7月期間發動大規模攻擊,全球超過3萬台設備遭入侵。該組織至少竊取了1,070萬美元的加密貨幣,由於使用了複雜的洗錢手法,實際損失總額可能更高。
據 BleepingComputer 報導,此次攻擊行動標誌著國家支持的金融網絡犯罪出現了策略性轉變。WaterPlum 放棄了針對知名加密貨幣交易所的做法,轉而採取大量散佈的「廣撒網」策略,從包括去中心化金融(DeFi)協議和個人錢包在內的廣泛、分散的受害者網絡中攫取較小額度的資金。
該行動的關鍵創新在於其對軟件供應鏈的複雜濫用。該組織專注於污染開源軟件倉庫並劫持合法的軟件更新機制,以此分發惡意軟件。這種方法能以極少的直接互動實現大規模攻擊,將受信任的開發基礎設施轉變為主要的初始入侵途徑。
黑客最初通過入侵路由器和防火牆等存在漏洞的邊緣設備取得立足點。隨後,他們部署常見且合法的管理工具進行指揮與控制(C2)活動。這種「借力打力」的策略使惡意流量能與正常網絡操作混合,顯著增加了安全團隊的偵測難度。
公告中引用的1,070萬美元數字被普遍認為是一個保守的底線。由於使用加密貨幣混幣器和跨鏈橋來模糊資金流向,總體的實際財務影響要大得多。這種混淆模式突顯了追蹤國家支持的盜竊行為所面臨的持久挑戰。
對於作為主要金融科技和虛擬資產中心的香港而言,此發展具有直接相關性。香港不斷擴大的數字資產生態系統,對採用這種分布式、專注供應鏈攻擊手法的組織來說,是一個誘人的目標。防禦者應注意,此威脅並不需要複雜的零日漏洞攻擊,而是利用軟件依賴管理及網絡設備衛生方面的常見弱點。
公告概述了組織必須採取的關鍵防禦措施。這些措施包括嚴格核實軟件依賴項及更新來源、監控邊緣設備的異常行為、以及審計常見系統管理工具的使用情況。實施網絡分段和零信任架構,也能限制成功入侵後的影響範圍。
WaterPlum 攻擊行動凸顯了對開源生態系統和標準 IT 工具的信任如何被武器化。隨著攻擊者從直接盜竊轉向系統性的供應鏈污染,防禦策略亦必須相應進化,以審查整個軟件生命週期的完整性。
