Recent investigations by the National Police Agency of Japan (NPA), the US Federal Bureau of Investigation (FBI), and other international cybersecurity agencies have revealed alarming activities by the North Korean cyber actor group known as “WaterPlum,” also referred to as “Contagious Interview.” This group is primarily targeting IT professionals globally, including in Japan, the United States, and Europe, with the intent to steal sensitive information and cryptocurrency assets. For more detailed information, refer to the advisory from the Australian Cyber Security Centre.
Overview of WaterPlum’s Tactics
The WaterPlum group employs deceptive recruitment strategies, posing as legitimate employers to lure software developers and IT professionals into their trap. They often impersonate companies in the fields of Artificial Intelligence (AI), cryptocurrency, and Non-Fungible Tokens (NFTs). During the recruitment process, candidates are asked to participate in technical interviews or complete coding assignments, which involve downloading and executing malicious files disguised as legitimate software.
Once the malware is executed, WaterPlum actors gain backdoor access to the victim’s computer systems. They utilize Remote Access Trojans (RATs) to maintain control and exfiltrate sensitive data, including cryptocurrency wallet credentials and personal information. Reports indicate that WaterPlum has compromised over 30,000 devices across more than 100 countries, successfully stealing funds from over 7,000 cryptocurrency wallets, amounting to approximately 1.7 billion Japanese yen (around 10.71 million USD).
Mitigation Strategies for IT Professionals
Given the sophisticated nature of WaterPlum’s operations, IT professionals and organizations must adopt stringent security measures to protect against these threats. Here are several recommended actions:
- Be Cautious with Downloads: Avoid executing code from untrusted sources, especially on machines handling sensitive data or cryptocurrency. Use sandbox environments for testing unknown code.
- Verify Recruitment Practices: Scrutinize job applications, especially those that arrive in bulk or from suspicious sources. Conduct thorough background checks and verify the authenticity of applicants’ credentials.
- Limit Access Rights: Implement strict access controls to sensitive information and systems. Ensure that only authorized personnel have access to critical data.
- Utilize Endpoint Detection Tools: Deploy Endpoint Detection and Response (EDR) solutions to monitor for unusual behavior and potential breaches within your network.
- Educate Employees: Conduct regular training sessions to raise awareness about phishing tactics and the importance of cybersecurity hygiene.
As the WaterPlum group continues to evolve its tactics, staying informed and vigilant is crucial for IT professionals and organizations alike. Regularly monitoring alerts from cybersecurity agencies and implementing the recommended security measures can significantly reduce the risk of falling victim to these sophisticated cyberattacks.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



