Threat Brief — 2026-09-24 — DPRK crypto heist quantified, multi-tech single-server campaign
Executive summary: A joint statement from seven law enforcement agencies across four countries has quantified the North Korean WaterPlum group's cryptocurrency theft at approximately $10.7 million from over 7,000 wallets — the first concrete financial attribution for a campaign first surfaced five days ago. Separately, researchers have documented a single IP address orchestrating months-long attacks pivoting across WordPress, Zyxel devices, and government systems worldwide. A lighter item worth noting: reports that Meta's AI assistant is in some cases operated by call-center humans rather than autonomous agents, raising trust and transparency concerns for organisations relying on AI-mediated customer interactions.
Top items
- WaterPlum (DPRK) crypto theft quantified at ~$10.7M across 7,000+ wallets. A joint statement by seven agencies from four countries confirms the North Korean group stole funds or credentials from over 7,000 cryptocurrency wallets and transferred approximately $10.71 million to Pyongyang. This is the first official financial quantification of the campaign, which was first reported on 2026-09-19 when the scope was described as 30,000 compromised devices. The multi-government attribution and dollar figure represent a meaningful escalation in public visibility. (src: xakep)
- Single-server campaign pivots across WordPress, Zyxel, and government targets. Researchers have identified a single IP address behind an operation that spent months rotating through multiple attack technologies — targeting WordPress sites, Zyxel network devices, and government systems globally. The sustained pivoting across diverse technology stacks from one infrastructure point suggests a capable operator or group testing and exploiting multiple vulnerability classes in sequence. This story was first reported today. (src: securitylab.ru)
- Meta AI assistant reportedly staffed by call-center humans in some cases. Users interacting with Meta's AI agent may unknowingly be communicating with a human call-centre worker rather than an autonomous system, with the substitution potentially discovered too late. While not a traditional vulnerability, this raises trust and transparency risks for organisations that interface with Meta's AI-mediated services or rely on similar agentic AI products for customer engagement. (src: securitylab.ru)
Themes
Deception across layers. All three items share a thread of hidden reality differing from the presented surface: WaterPlum's campaign used fake interview infrastructure to compromise developers; the single-server campaign masked months of multi-vector attacks behind one IP; and Meta's "AI" assistant conceals human operators. For defenders, the takeaway is that threat actors and vendors alike can present a surface that diverges significantly from what is actually operating underneath — reinforcing the value of independent verification over trust in presented interfaces.
