Skip to main content
AVOID.NET

WaterPlum / Contagious Interview

avoid.net/waterplum-contagious-interview0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5QNKVX…BJKf

Summary

WaterPlum, the name given by a seven-agency international joint advisory to the threat group the security industry had previously tracked as Contagious Interview, is a North Korean state-linked cyber-espionage and theft operation assessed to operate under the 313 General Bureau of North Korea's Munitions Industry Department. Between December 2025 and July 2026 the group infected more than 30,000 devices in over 100 countries by posing as recruiters for AI, cryptocurrency, and NFT companies, tricking developers into executing malicious code during fake technical interviews and transferring at least $10.71 million USD (approximately 1.7 billion JPY) in stolen cryptocurrency to North Korea. The campaign is attributed by the FBI, Japan's National Police Agency, Australia's ASD ACSC, and German intelligence agencies; it remains ongoing and actively targets software developers and crypto/Web3 job seekers.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about WaterPlum / Contagious Interview?

Timeline(7 events)

1 January 2022

Security researchers first document Contagious Interview campaign targeting developers via fake job offers and malicious npm packages; exact start date is approximate.

Socket.dev / multiple threat-intelligence firms

1 January 2025

A North Korean IT-worker posing as a Malaysian national attempts to gain employment at Japanese cryptocurrency exchange bitFlyer; the applicant uses multiple VPNs, requests cryptocurrency payment, and ultimately declines the position. Date is approximate based on NPA disclosure.

Japan NPA via CryptoTimes

1 December 2025

Start of the campaign window documented in the joint government advisory: WaterPlum begins systematically infecting devices at scale across 100+ countries.

Joint advisory per CoinTelegraph

31 July 2026

End of the advisory's documented campaign window. By this date: 30,000+ devices infected, 7,000+ crypto wallets compromised, $10.71 million USD transferred to North Korea.

Joint advisory per CoinTelegraph / CryptoTimes

18 September 2026

Seven agencies — Japan NPA, Japan NCO, FBI, DC3, ASD ACSC, Germany BND, Germany BfV — publish joint advisory formally attributing WaterPlum to North Korea's 313 General Bureau and disclosing scale and financial figures.

Joint advisory per CryptoTimes / cyber.gov.au

18 September 2026

Japan's NPA separately discloses that authorities identified and dismantled a North Korean IT-worker laptop farm on Japanese soil for the first time.

CryptoTimes

21 September 2026

Continued reporting on the advisory; FBI and international partners publicly confirm the campaign is ongoing and actively targeting developers as of this date.

Daily Hodl / CoinTelegraph
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/21/2026, 11:05:33 PM

last updated: 9/22/2026, 5:01:54 AM

avoid.net — verified advice for a post-truth world