Threats & Adversaries · APT / Espionage

WaterPlum Turns Hiring into Corporate Access

U.S. and allied agencies said WaterPlum, also called Contagious Interview, is running a long campaign through fake employers, recruiter outreach, and contractor work, and tied the activity to North Korea’s 313 General Bureau. The coordinated alert puts the operation at more than 30,000 infected devices across 100 countries and more than $10 million taken from over 7,000 crypto wallets.

The lure is ordinary hiring work: applicants are asked to open job files, coding tests, or other interview materials, and that step delivers malware that steals wallet data and can keep access on the machine. The same pattern also overlaps with North Korean IT-worker placements, where stolen identities and access help the group move from personal devices into corporate web systems.

For technology companies that hire through recruiters, tests, or freelance channels, the trust boundary is not just the inbox. A compromised candidate device can carry stolen credentials and persistence into a later employer environment, so the reporting leaves the exposure sitting in the recruiting and contractor pipeline as much as on the endpoint.

4 sources · Sep 19

Timeline

Sources

Part of the PlainSec briefing for 2026-09-19

Every edition of this story: WaterPlum Turns Hiring into Corporate Access

More from today