CyberzSOC

Publication detail
← Back to advisories & guidance

North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals ↗ source

September 18, 2026 ASD/ACSC Advisory

Summary

The National Police Agency of Japan (NPA), the National Cybersecurity Office of Japan (NCO), the US Federal Bureau of Investigation (FBI) and the US Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), Germany Federal Intelligence Service (BND) and Germany Federal Office for the Protection of the Constitution (BfV) have determined the following: The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries. The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities. They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.