INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Contagious Interview Compromises 30,000 Devices
| 2026-09-22 06:44 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The threat landscape is evolving rapidly, with new and sophisticated attacks emerging from North Korea. WaterPlum, a group linked to the country's intelligence agency, has been behind several high-profile cyberattacks targeting devices across multiple countries. The group's tactics include impersonating legitimate companies as recruiters or hiring managers, using social media platforms and job boards to lure victims into their trap. With over 30,000 compromised devices worldwide, funds stolen from cryptocurrency wallets worth billions of dollars, and a total of $10.71 million funneled back to North Korea, the situation is dire. The US Federal Bureau of Investigation (FBI) has been working closely with international partners to bring WaterPlum's operators to justice, while also addressing the broader threat posed by this sophisticated cyberattack.
Technical Mitigations AI-generated
* Use reputable antivirus software and keep it up to date to prevent malware infections.
* Be cautious when opening emails, attachments, or links from unknown sources, as they may contain malicious files or downloads.
* Avoid using public Wi-Fi networks for sensitive activities such as online banking, shopping, or accessing confidential information.
* Regularly back up important data to a secure location, such as an external hard drive or cloud storage service, to prevent loss in case of a cyberattack.
* Use strong and unique passwords for all accounts, and avoid using the same password across multiple sites; consider using a password manager to generate and store complex passwords.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview
InvisibleFerretInvisibleFerretBeaverTailBeaverTail
Target & Sectors
FIVE_EYES
FIVE_EYES
LATAM
LATAM
AFRICA
AFRICA
DACH
DACH
NORDICS
NORDICS
NORTH_AMERICA
NORTH_AMERICA
DPRK
DPRK
cryptocurrencycryptocurrency
governmentgovernment
Incident Timeline
May 2025
North Korea's IT workers were found to be using the same IP addresses for various online activities including job applications and cryptocurrency exchanges.
Click on any entity below to view its context and source!
target_region
Japan
The advisory also describes a case involving a Japanese crypto exchange that spotted one of these applicants in May 2025.
threat_actor
Contagious Interview
“Stay informed by monitoring alerts from domestic and international security agencies and by reviewing reports published by security vendors.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– Contagious Interview, WaterPlum)
organisation
IP
They’ve been caught using the same IP addresses to access laptop farms, register on freelance platforms, and apply for that same crypto exchange job.
June 2025
Threat actors used fake job postings to infect 30,000 devices with malware.
Click on any entity below to view its context and source!
source_region
DPRK
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
general_metric
313 General Bureau
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
organisation
PurpleDelta
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
organisation
the 313 General Bureau
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
organisation
the Munitions Industry Department
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
organisation
DTEX
It's suspected that both WaterPlum and
some North Korean IT workers
(aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a
June 2025 assessment
from DTEX.
July 2026
Threat actors used VPN services like Astrill VPN and Mullvad to obtain exit nodes in Japan.
Click on any entity below to view its context and source!
source_region
Japan
According to a July 2026 analysis of the
internal infrastructure
linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.
organisation
Kudelski Security
According to a July 2026 analysis of the
internal infrastructure
linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.
organisation
Astrill VPN
According to a July 2026 analysis of the
internal infrastructure
linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.
2026/09/14
Threat actors used a fake job interview platform to target 30,000 devices in the U.S., E.U. and Latin America by hiring individuals as proxies for job interviews.
Click on any entity below to view its context and source!
source_region
DPRK
In a report published last week, Silent Push said it identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named "Mouse Review," specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews so as to get around sanctions, geographic blocks, and compliance checks.
source_region
LATAM
In a report published last week, Silent Push said it identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named "Mouse Review," specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews so as to get around sanctions, geographic blocks, and compliance checks.
organisation
Discord
In a report published last week, Silent Push said it identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named "Mouse Review," specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews so as to get around sanctions, geographic blocks, and compliance checks.
September 18
Threat actors used a fake job interview website to infect 30,000 devices.
Click on any entity below to view its context and source!
threat_actor
Contagious Interview
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
target_region
Japan
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
target_region
United States
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
target_region
Australia
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
target_region
Germany
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
industry
Defense
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
attribution
Japan’s National Police Agency
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
attribution
FBI
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
attribution
the US Department of Defense’s Cyber Crime Center
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
attribution
WaterPlum
On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as
Contagious Interview
.
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices worldwide using a fake job interview.
Click on any entity below to view its context and source!
source_region
Korea, Democratic People's Republic of
Contagious Interview: 30,000 devices infected by a fake job interview
Pierluigi Paganini
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
source_region
DPRK
Contagious Interview: 30,000 devices infected by a fake job interview
Pierluigi Paganini
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
threat_actor
Contagious Interview
Contagious Interview: 30,000 devices infected by a fake job interview
Pierluigi Paganini
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
infrastructure
30,000 devices
Contagious Interview: 30,000 devices infected by a fake job interview
Pierluigi Paganini
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
At least 30,000 devices infected across more than 100 countries, funds or credentials stolen from over 7,000 cryptocurrency wallets, and a total of 1.7 billion yen, roughly $10.71 million, funneled back to North Korea.
“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.
organisation
the Democratic People’s Republic of Korea
WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).”
organisation
NFT
WaterPlum actors pose as recruiters or hiring managers, often impersonating real AI, crypto, or NFT companies, and reach out on social media, job boards, and freelance platforms.
organisation
OtterCandy
The advisory names five malware families riding inside these downloads,
BeaverTail
,
InvisibleFerret
,
OtterCookie
, OtterCandy, and
StoatWaffle
, each doing its own piece of the job: one steals browser credentials, another opens a backdoor, another sets up a remote access trojan to move deeper into the machine.
organisation
StoatWaffle
The advisory names five malware families riding inside these downloads,
BeaverTail
,
InvisibleFerret
,
OtterCookie
, OtterCandy, and
StoatWaffle
, each doing its own piece of the job: one steals browser credentials, another opens a backdoor, another sets up a remote access trojan to move deeper into the machine.
2026/09/22
WaterPlum used online chat platforms to communicate with U.S. and Japanese developers, while employing enablers in Japan, the U.S., and other countries to set up and manage laptop farms for remote device management.
Click on any entity below to view its context and source!
organisation
KYC
"
"The North Korean IT worker's primary goal is proxy hiring, using Western or Latin American (LATAM) citizens as the 'face' and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions," Silent Push
said
.
threat_actor
Contagious Interview
The North Korean threat actors behind the
Contagious Interview
campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new
joint cybersecurity advisory
.
Contagious Interview: 30,000 devices infected by a fake job interview.
Contagious Interview, first
exposed
by Palo Alto Networks Unit 42, is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the wild by posing as prospective employers and recruiters, and approaching them on social media platforms like LinkedIn under the pretext of lucrative job offers.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto.
infrastructure
30,000 devices
The North Korean threat actors behind the
Contagious Interview
campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new
joint cybersecurity advisory
.
Contagious Interview: 30,000 devices infected by a fake job interview.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto.
organisation
Palo Alto Networks Unit
Contagious Interview, first
exposed
by Palo Alto Networks Unit 42, is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the wild by posing as prospective employers and recruiters, and approaching them on social media platforms like LinkedIn under the pretext of lucrative job offers.
organisation
LinkedIn
Contagious Interview, first
exposed
by Palo Alto Networks Unit 42, is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the wild by posing as prospective employers and recruiters, and approaching them on social media platforms like LinkedIn under the pretext of lucrative job offers.
organisation
IP
What's more, the two clusters are said to be deeply intertwined, in some cases using the same IP addresses when accessing laptop farms and applying for positions at Japanese cryptocurrency exchanges.
organisation
Discord for Recruiting Proxies
"
IT Worker Threat Expands to Discord for Recruiting Proxies
Complementing North Korea's offensive cyber capabilities is the
infamous IT worker scheme
, which is tasked with generating illicit revenue for the regime by landing jobs in Western companies and elsewhere under false identities.
organisation
StoatWaffle
Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including
BeaverTail, InvisibleFerret
,
FlexibleFerret
,
GolangGhost, PylangGhost
,
OtterCookie
,
RATatouille, OtterCandy
, and
StoatWaffle
.
organisation
GolangGhost
Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including
BeaverTail, InvisibleFerret
,
FlexibleFerret
,
GolangGhost, PylangGhost
,
OtterCookie
,
RATatouille, OtterCandy
, and
StoatWaffle
.
organisation
PylangGhost
Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including
BeaverTail, InvisibleFerret
,
FlexibleFerret
,
GolangGhost, PylangGhost
,
OtterCookie
,
RATatouille, OtterCandy
, and
StoatWaffle
.
organisation
CL-STA-0240
The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
organisation
DeceptiveDevelopment
The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
organisation
PurpleBravo
The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
organisation
Void Dokkaebi
The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Click for context!
Contagious Interview: 30,000 devices infected by a fake job interview
Pierluigi Paganini
September 22, 2026
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
At least 30,000 devices infected across more than 100 countries, funds or credentials stolen from over 7,000 cryptocurrency wallets, and a total of 1.7 billion yen, roughly $10.71 million, funneled back to North Korea.
Contagious Interview: 30,000 devices infected by a fake job interview.
“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto.
The North Korean threat actors behind the
Contagious Interview
campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new
joint cybersecurity advisory
.
Intelligence Sources
Security Affairs
2026-09-22
The Hacker News
2026-09-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-22T12:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
NFT
entity
10x
target region
Target Country
Japan
country
9x
attribution
Attributing Entity
Japan’s National Police Agency
authority
8x
timeline
Temporal Reference
September 22, 2026
date
4x
tactic
Cyber Operation Type
Exfiltration
tactic
3x
industry
Targeted Sector
Defense
sector
3x
target region
Target Region
DPRK
region
2x
source region
Origin Country
Korea, Democratic People's Republic of
country
2x
source region
Origin Region
DPRK
region
2x
malware
Malware Payload
BeaverTail
tool
2x
general metric
%
35
%
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
Contagious Interview
actor
infrastructure
Devices
30,000
devices
general metric
Countries
100
countries
general metric
Cryptocurrency Wallets
7,000
cryptocurrency wallets
general metric
Yen
1,700,000,000
yen
general metric
General Bureau
313
general bureau
tactic
MITRE ATT&CK Technique
T1588.007 - Artificial Intelligence
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.