WaterPlum / Contagious Interview
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5QNKVX…BJKfSummary
WaterPlum, the name given by a seven-agency international joint advisory to the threat group the security industry had previously tracked as Contagious Interview, is a North Korean state-linked cyber-espionage and theft operation assessed to operate under the 313 General Bureau of North Korea's Munitions Industry Department. Between December 2025 and July 2026 the group infected more than 30,000 devices in over 100 countries by posing as recruiters for AI, cryptocurrency, and NFT companies, tricking developers into executing malicious code during fake technical interviews and transferring at least $10.71 million USD (approximately 1.7 billion JPY) in stolen cryptocurrency to North Korea. The campaign is attributed by the FBI, Japan's National Police Agency, Australia's ASD ACSC, and German intelligence agencies; it remains ongoing and actively targets software developers and crypto/Web3 job seekers.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(7 events)
1 January 2022
Security researchers first document Contagious Interview campaign targeting developers via fake job offers and malicious npm packages; exact start date is approximate.
Socket.dev / multiple threat-intelligence firms1 January 2025
A North Korean IT-worker posing as a Malaysian national attempts to gain employment at Japanese cryptocurrency exchange bitFlyer; the applicant uses multiple VPNs, requests cryptocurrency payment, and ultimately declines the position. Date is approximate based on NPA disclosure.
Japan NPA via CryptoTimes1 December 2025
Start of the campaign window documented in the joint government advisory: WaterPlum begins systematically infecting devices at scale across 100+ countries.
Joint advisory per CoinTelegraph31 July 2026
End of the advisory's documented campaign window. By this date: 30,000+ devices infected, 7,000+ crypto wallets compromised, $10.71 million USD transferred to North Korea.
Joint advisory per CoinTelegraph / CryptoTimes18 September 2026
Seven agencies — Japan NPA, Japan NCO, FBI, DC3, ASD ACSC, Germany BND, Germany BfV — publish joint advisory formally attributing WaterPlum to North Korea's 313 General Bureau and disclosing scale and financial figures.
Joint advisory per CryptoTimes / cyber.gov.au18 September 2026
Japan's NPA separately discloses that authorities identified and dismantled a North Korean IT-worker laptop farm on Japanese soil for the first time.
CryptoTimes21 September 2026
Continued reporting on the advisory; FBI and international partners publicly confirm the campaign is ongoing and actively targeting developers as of this date.
Daily Hodl / CoinTelegraphDecision Log
- hash: HJDBUt8XWu7gftcYaHAXPx9iHNLvpjPzk1Xa11voL7L6
This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/21/2026, 11:05:33 PM
last updated: 9/22/2026, 5:01:54 AM
avoid.net — verified advice for a post-truth world