🇯🇵🇺🇸🇦🇺🇩🇪 On Sep 18, Japan’s NPA and National Cybersecurity Office, the U.S. FBI and DC3, Australia’s ASD/ACSC, and Germany’s BND and BfV jointly released a report on North Korea-linked #
WaterPlum#, also known as “Contagious Interview” .
SlowMist analyzed the report, examining the links between fake-job phishing, malware attacks, and “Laptop Farm” operations.
📄 Official report:
🔎 What the report reveals
• Dec 2025–Jul 2026: 30,000+ computers infected across 100+ countries and regions
• Data from 7,000+ crypto wallets stolen; at least JPY 1.7B (~USD 10.71M) flowed into wallets controlled by WaterPlum
• Fake technical interviews can be used to deliver malware, steal credentials and wallet data, and enable further intrusion into corporate networks
• Japan disclosed its first Laptop Farm seizure and dismantling
👤 For individuals / freelancers
Don’t run unfamiliar interview code on machines holding wallets or sensitive work data. If an alert fires, disconnect from the internet first.
🏢 For hiring / outsourcing teams
Treat unusually broad résumés, crypto-only payment requests, and refusal to work on-site as security signals worth investigating.
📖 Full analysis: