Cyber Resilience
← All news
Confirmed

North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals

Our takeJoint advisory from the US, Australia, Japan and Germany details North Korean WaterPlum operators posing as AI and blockchain employers to deliver malware and steal crypto from job applicants. They compromised at least 30 000 devices and moved over $10.7 M. No mechanism has been disclosed for any AI-powered element of the campaign.
Sources (6)
What this means for you — Security leader:Review job application and interview processes for remote/contractor roles. Train recruiters and hiring managers to spot fake-company lures and never accept unsolicited code, tools, or wallet connections from candidates.
What this means for you — Lean IT orgs:If you or your team apply for tech jobs, only use official company domains and never run code, browser extensions, or crypto wallets supplied during an interview. Verify every offer through a known, trusted contact before proceeding.
What this means for you — MSP:Advise clients to treat unsolicited remote IT/contractor interviews as high risk. Add controls that block execution of candidate-supplied binaries and monitor for unusual wallet or crypto activity on employee endpoints.
What this means for you — Researcher:Track the joint advisory’s indicators and TTPs; the campaign’s scale (30 k+ infections, $10.7 m crypto exfiltrated) makes the IoCs high-value for detection engineering.