IC Technology & Cyber — 2026-09-20

Four Nations Attribute Contagious Interview Fake-Job Malware Campaign to North Korea WaterPlum Group

BLUFFormal four-nation attribution to the 313 General Bureau gives allied governments and platform operators a legal foundation to prosecute facilitators and disrupt North Korean revenue pipelines beyond mere disclosure.

On September 18, Japan's National Police Agency and National Cybersecurity Office, the FBI, the Defense Department's Cyber Crime Center, Australia's Cyber Security Centre, and Germany's BND and BfV issued a joint advisory attributing the "Contagious Interview" fake-job malware campaign to a North Korean group they name WaterPlum 12. The agencies assess WaterPlum falls under the 313 General Bureau of North Korea's Munitions Industry Department and say the campaign infected more than 30,000 devices in over 100 countries, compromising roughly 7,000 cryptocurrency accounts and diverting about 1.7 billion yen ($10.7 million) to North Korea, with the most intense activity between December 2025 and July 2026 34. The advisory names five malware families, BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, delivered through malicious npm packages after operators posing as AI, crypto and NFT recruiters direct applicants to run coding tests or troubleshoot video calls 34. Japanese police say they dismantled a domestic laptop farm supporting North Korean IT workers who used stolen identities and VPS infrastructure to secure remote contracts, and Japan's Foreign Ministry said it will expand cooperation with allied governments and the private sector 23.

Analysis
The joint attribution, resting on independently corroborating primary releases from Washington and Tokyo rather than one echoing the other, converts a technical campaign into a formal interstate accusation, giving the four governments documented grounds for sanctions, indictments and platform-level enforcement against npm and code-hosting infrastructure. Linking the malware campaign and the IT-worker scheme through shared IP ranges and laptop farms under one 313 General Bureau revenue apparatus shifts liability onto employers and platforms that fail to screen contractors or scan packages; Japan's dismantling of a domestic laptop farm shows enforcement capacity now reaches inside allied territory. The decentralized, freelance tradecraft, npm-based lures and crypto-recruiter fronts, resembles criminal franchising as much as centralized state direction, leaving Pyongyang's operational control asserted rather than demonstrated.
5 sources
  1. North Korean "WaterPlum," commonly referred to as "Contagious Interview," Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe - FBI/IC3 (Internet Crime Complaint Center)
  2. Public Attribution on North Korean Cyber Actor Group "WaterPlum," and North Korean IT Workers - Ministry of Foreign Affairs of Japan
  3. Four Countries Attribute Contagious Interview Fake-Job Malware Campaign to North Korea WaterPlum - The Cyber Express
  4. North Korea's WaterPlum hackers stole $10.7M in crypto, Japan and allies say - Cryptopolitan
  5. International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data - CyberScoop

View in full brief →

UNCLASSIFIED // OPEN SOURCE