FBI and Allied Agencies Jointly Attribute North Korean WaterPlum Job-Seeker Malware Campaign Infecting 30000 Devices Across 100 Countries
The FBI, DoD Cyber Crime Center, and cybersecurity agencies in Japan, Australia, and Germany jointly attributed a North Korean hacking campaign tracked as WaterPlum or Contagious Interview to the
The joint advisory formalizes what open-source trackers described piecemeal since 2023: Contagious Interview functions as an operating arm of North Korea's sanctioned IT-worker export apparatus rather than a discrete hacking campaign, fusing credential theft with illicit overseas employment. Shared IP infrastructure linking WaterPlum to crowdsourcing-platform accounts and laptop farms indicates the same operator pool runs both the malware lures and the freelance-contract fraud funding weapons programs, shifting exposure from government networks to hiring pipelines, npm registries, and extension marketplaces that now function as sanctioned-actor infrastructure. The FBI/IC3 advisory, co-issued with Japanese, Australian, and German counterparts, is the sole primary source; wire outlets republish its figures without independent corroboration. The 30,000-device, 100-country, $11 million tally may reflect cumulative activity tracked since 2023 rather than a discrete surge within this reporting window. Recruiters and individual developers, not just enterprise security teams, now sit on the front line of this sanctions-evasion economy.
9 sources
- International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data -
CyberScoop - North Korean hackers infect thousands of devices across 100 countries as part of 'WaterPlum' campaign -
The Record (Recorded Future News) - IC3: North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto -
Rankiteo Blog - North Korean WaterPlum hackers infected 30,000 devices worldwide -
BleepingComputer - North Korea's fake job interviews infected 30,000 devices -
The Register - North Korea's fake job interviews infected 30,000 devices -
The Register - North Korean fake recruiters infect 30,000 devices worldwide -
Cybernews - North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs -
Tom's Hardware - North Korean "WaterPlum," commonly referred to as "Contagious Interview," cyber actor group targeting IT professionals -
FBI/IC3 (joint Cybersecurity Advisory with Japan's National Police Agency & National Cybersecurity Office, Australia's ACSC, Germany's BfV/BND, and the U.S. DoD Cyber Crime Center)