On the 18th, security agencies from Japan, the United States, Australia, Germany, and other nations issued a joint alert regarding “WaterPlum,” a North Korea-linked hacking group. The group targets software developers and IT professionals worldwide under the guise of “job interviews.” Dubbed “Contagious Interview,” the campaign involves hackers posing as HR representatives or recruiters from AI, cryptocurrency, or NFT companies to contact targets via social media, job boards, and freelance platforms.
Investigations reveal that during supposed technical interviews or assessment tasks, victims are asked to download and execute malicious files or process code ostensibly designed to troubleshoot video conferencing issues. Attackers use this method to plant various types of malware—including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle—to steal browser-stored credentials, clipboard data, keystrokes, screenshots, wallet keys, recovery phrases, identity documents, and source code.
Security agencies estimate that between December 2025 and July 2026, WaterPlum infected over 30,000 devices across more than 100 countries and regions, with victims located in Japan, the U.S., Europe, and elsewhere. The group stole approximately $10.7 million (equivalent to 1.7 billion yen) in assets from over 7,000 cryptocurrency wallets. Authorities noted that the group is linked to the 313th General Bureau of the Munitions Industry Department under the Workers’ Party of Korea, indicating that these attacks are not merely cybercrimes but also serve as a means for North Korea to acquire foreign currency.
Japanese police and international partners advise job seekers to remain vigilant if, during an interview, they are asked to run unknown programs, if the interviewer refuses an in-person meeting, if there are frequent audio or video anomalies, or if salary payment is requested in cryptocurrency. Companies are advised to verify whether an applicant’s IP address matches their claimed location and to watch for suspicious signs such as voice modulation, deepfake technology, or the use of remote proxies to impersonate the candidate.
