What Happened
The FBI, the US Department of Defense’s Cyber Crime Center, and security agencies in Japan, Germany, and Australia issued a joint advisory on WaterPlum, also tracked as Contagious Interview, a North Korean hacking group operating under the 313 General Bureau of the Munitions Industry Department. The group poses as prospective employers, frequently impersonating artificial intelligence, cryptocurrency, or NFT companies, and lures software developers and IT professionals through fake job interviews and coding tests delivering malware. The advisory describes substantial overlap between WaterPlum operators and North Korea’s broader fraudulent IT-worker scheme, including shared infrastructure used to access “laptop farms” and cloud services. Agencies report the group has infected more than 30,000 devices across over 100 countries and moved nearly $11 million in cryptocurrency from over 7,000 compromised wallets back to North Korea, with Japanese authorities announcing the country’s first dismantling of a laptop farm tied to the operation. Read the advisory summary from CyberScoop.
Why This Matters for Canadian Organizations
Canada was not named among the agencies behind Friday’s advisory, but WaterPlum’s targeting criteria, developers, IT professionals, and cryptocurrency businesses, describe a workforce Canada’s technology sector relies on heavily, including remote contractors hired sight unseen. Canadian crypto and AI startups posting remote developer roles sit squarely in the group’s impersonation pattern, and Canadian job seekers submitting code samples or running “test” projects from unfamiliar recruiters face the same infection risk documented in the US, Japan, Germany, and Australia. The overlap with North Korea’s IT-worker fraud scheme also raises a hiring-side risk: Canadian companies hiring remote developers face exposure to sanctioned workers using stolen or fabricated identities, a concern CCCS has flagged in prior guidance on North Korean cyber activity.
What to Do
Technology and cryptocurrency employers should verify remote candidates’ identities through video interviews and independent reference checks before granting code-repository or system access, and should run any pre-employment coding assignments in an isolated environment rather than on a primary work device. Job seekers, especially developers approached with unsolicited AI, crypto, or NFT opportunities, should treat requests to download and run unfamiliar “test” applications or scripts with suspicion and verify a recruiter’s identity and company independently before proceeding. Security teams should watch for the infrastructure patterns described in the joint advisory, including shared IP usage across recruiting platforms and cloud services.






