Minacce · 2 giorni fa
Le agenzie di Australia, Germania, Giappone e Stati Uniti hanno attribuito a WaterPlum, gruppo nordcoreano noto anche come Contagious Interview, una campagna che ha infettato circa 30.000 dispositivi e sottratto oltre 10 milioni di dollari in crypto. Il salto di oggi è nella scala e nel modello: non solo furto ai candidati, ma un canale monetizzato che passa da recruiting e contractor.
WaterPlum si presenta come datore di lavoro o cliente, poi spinge il bersaglio ad aprire file o svolgere task di colloquio. In quel passaggio entra il malware, che ruba wallet e dati sensibili e può restare sul dispositivo per usi successivi. Le agenzie dicono anche che alcuni operatori si sovrappongono ai North Korean IT workers e usano incarichi web reali per restare agganciati agli ambienti corporate.
Per chi usa screening da remoto, coding test o intake di freelance, il rischio non finisce sul laptop personale del candidato. Un dispositivo compromesso può portarsi dietro credenziali, wallet access e persistenza quando quella persona viene assunta o lavora per un cliente. Il canale di assunzione diventa così parte della superficie d’ingresso dell’azienda.
4 fonti che coprono questa storia
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
North Korea's fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
International security agencies warned that North Korean hacker group WaterPlum is posing as prospective employers to target job seekers and steal millions in cryptocurrency.
The Record from Recorded Future
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
Part of the PlainSec briefing for 2026-09-21