INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Contagious Interview Compromises 30,000 Devices

| 2026-09-22 06:44 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The threat landscape is evolving rapidly, with new and sophisticated attacks emerging from North Korea. WaterPlum, a group linked to the country's intelligence agency, has been behind several high-profile cyberattacks targeting devices across multiple countries. The group's tactics include impersonating legitimate companies as recruiters or hiring managers, using social media platforms and job boards to lure victims into their trap. With over 30,000 compromised devices worldwide, funds stolen from cryptocurrency wallets worth billions of dollars, and a total of $10.71 million funneled back to North Korea, the situation is dire. The US Federal Bureau of Investigation (FBI) has been working closely with international partners to bring WaterPlum's operators to justice, while also addressing the broader threat posed by this sophisticated cyberattack.
Technical Mitigations AI-generated
* Use reputable antivirus software and keep it up to date to prevent malware infections. * Be cautious when opening emails, attachments, or links from unknown sources, as they may contain malicious files or downloads. * Avoid using public Wi-Fi networks for sensitive activities such as online banking, shopping, or accessing confidential information. * Regularly back up important data to a secure location, such as an external hard drive or cloud storage service, to prevent loss in case of a cyberattack. * Use strong and unique passwords for all accounts, and avoid using the same password across multiple sites; consider using a password manager to generate and store complex passwords.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview InvisibleFerretInvisibleFerretBeaverTailBeaverTail
Target & Sectors
FIVE_EYES FIVE_EYES LATAM LATAM AFRICA AFRICA DACH DACH NORDICS NORDICS NORTH_AMERICA NORTH_AMERICA DPRK DPRK cryptocurrencycryptocurrency governmentgovernment
Incident Timeline
‎May 2025
North Korea's IT workers were found to be using the same IP addresses for various online activities including job applications and cryptocurrency exchanges.
target_region Japan
threat_actor Contagious Interview
organisation IP
‎June 2025
Threat actors used fake job postings to infect 30,000 devices with malware.
source_region DPRK
general_metric 313 General Bureau
organisation PurpleDelta
organisation the 313 General Bureau
organisation the Munitions Industry Department
organisation DTEX
‎July 2026
Threat actors used VPN services like Astrill VPN and Mullvad to obtain exit nodes in Japan.
source_region Japan
organisation Kudelski Security
organisation Astrill VPN
‎2026/09/14
Threat actors used a fake job interview platform to target 30,000 devices in the U.S., E.U. and Latin America by hiring individuals as proxies for job interviews.
source_region DPRK
source_region LATAM
organisation Discord
‎September 18
Threat actors used a fake job interview website to infect 30,000 devices.
threat_actor Contagious Interview
target_region Japan
target_region United States
target_region Australia
target_region Germany
industry Defense
attribution Japan’s National Police Agency
attribution FBI
attribution the US Department of Defense’s Cyber Crime Center
attribution WaterPlum
‎September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices worldwide using a fake job interview.
source_region Korea, Democratic People's Republic of
source_region DPRK
threat_actor Contagious Interview
infrastructure 30,000 devices
organisation the Democratic People’s Republic of Korea
organisation NFT
organisation OtterCandy
organisation StoatWaffle
‎2026/09/22
WaterPlum used online chat platforms to communicate with U.S. and Japanese developers, while employing enablers in Japan, the U.S., and other countries to set up and manage laptop farms for remote device management.
organisation KYC
threat_actor Contagious Interview
infrastructure 30,000 devices
organisation Palo Alto Networks Unit
organisation LinkedIn
organisation IP
organisation Discord for Recruiting Proxies
organisation StoatWaffle
organisation GolangGhost
organisation PylangGhost
organisation CL-STA-0240
organisation DeceptiveDevelopment
organisation PurpleBravo
organisation Void Dokkaebi
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Intelligence Sources