MALAYSIA, 30 SEPTEMBER 2026 – A joint security advisory issued by international intelligence bodies including the US Federal Bureau of Investigation (FBI), Japan National Police Agency (NPA), Australian Signals Directorate (ASD), and German intelligence services has exposed a widespread cyber exploitation campaign orchestrated by North Korea state-linked threat group WaterPlum, also known as Contagious Interview.
The sophisticated syndicate operates under the 313 General Bureau of the Munitions Industry Department of North Korea. By posing as legitimate recruiters for Artificial Intelligence, Web3, and cryptocurrency firms, operatives target software developers and tech contractors worldwide through fake online job interviews and technical assessment coding tasks.
During remote recruitment processes, job applicants are tricked into downloading malicious coding packages embedded with specialized malware variants such as BeaverTail and InvisibleFerret. Once installed, these tools grant actors remote backdoor access to personal and corporate systems, enabling the theft of browser credentials, key-logs, identity documents, and cryptocurrency private keys.
According to findings gathered between December 2025 and July 2026, the group successfully compromised devices in over 100 countries, exfiltrating assets from more than 7,000 digital wallets. Total direct crypto assets funneled back to Pyongyang reached USD 10.71 million (MYR 47.12 million). Investigative updates reveal that actors also leveraged international laptop farms located in private residences to obscure their actual physical locations in North Korea, China, or Russia while securing legitimate IT service contracts.
Security agencies highlighted various red flags observed during remote interviews, such as applicants using AI face-swapping software, displaying mismatched language capabilities compared to their resume, refusing in-person meetings, or requesting payments strictly in cryptocurrency routed through third-party accounts. In one specific instance in May 2025, a suspect claiming to be born in Malaysia and residing in Finland applied to a Japanese cryptocurrency exchange with a fabricated resume before being turned away.
Authorities urge tech organizations, freelancers, and businesses utilizing global crowdsourcing marketplaces to apply strict security measures. Recommended steps include running untrusted code only in isolated sandbox environments, auditing external project files before execution, deploying Endpoint Detection and Response tools, and thoroughly verifying subcontractor identities to mitigate espionage and financial losses.
