Security1 publisher2 min readPublished
Joint advisory pins WaterPlum's fake recruiters to North Korea's 313 General Bureau
Four governments have put a bureau name on the fake-recruiter campaign against software developers, and their alert says the same crews also work as North Korea's remote IT hires, from the same IP addresses.
The Watch · Security desk

What happened
- A joint advisory attributes the group tracked as WaterPlum, or Contagious Interview, to the 313 General Bureau of the Munitions Industry Department, subordinate to the Workers Party of Korea's Central Committee.
- CyberScoop reports the group has infiltrated tens of thousands of job seekers' computer networks by posing as prospective employers, including artificial intelligence firms.
- The agencies count more than 30,000 infected devices across more than 100 countries, with IT professionals in Japan, the United States and Europe among the targets.
- Nearly $11 million equivalent in cryptocurrency has moved from more than 7,000 wallets to North Korea, according to the alert.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Recruitment contact is now a documented intrusion path into software developers and IT staff. A job approach to an engineer is not traffic most security teams inspect, and it reaches people who hold production credentials.
- decision Candidate vetting and threat hunting are looking at one set of IP addresses, so companies that run remote hiring and endpoint defence as separate programs are splitting a single problem across two budgets.
- constraint At under $1,600 per wallet, no individual theft is large enough to pull an investigator, so anything that catches this has to work on the endpoint or in the hiring channel before the money moves.
- precedent Prosecution is landing on the local facilitator. Laptop farm hosts in other countries are the next people who can expect charges.
The same operators sit on both sides of a hiring process. "Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients," the agencies wrote [6]. They also placed the two programs on shared infrastructure: "WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange" [7]. The overlap is substantial, the agencies said, and stolen information fed other operations [18].
The pretext is a job offer. "WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities," the alert said [4]. "They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services" [5]. CyberScoop, in its account of the alert, did not name the malware families. The agencies said they had some success against the group, released its tactics, techniques and procedures, and are seeking further cooperation [14].
Averaged out, each drained wallet gave up a little under $1,600 [15]. Losses that size rarely produce a police report on their own. The eleven-million-dollar figure exists because agencies in four countries added them together [9].
Those four are Japan, Australia, Germany and the United States, where both the FBI and the Defense Department's Cyber Crime Center signed [3][16]. What the alert adds to what was already public about Contagious Interview is a named military-industrial bureau where the record had a tracking label [2].
Enforcement so far has landed on the enablers. "For the first time in Japan, authorities successfully identified, investigated, and dismantled a 'laptop farm' operated by an enabler in Japan," the alert said [10]. Japanese authorities obtained evidence that the group moved several hundred million yen in cryptocurrency to locations outside Japan [11]. The FBI said it continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers [12]. Separately, the Multilateral Sanctions Monitoring Team, the panel overseeing UN sanctions on North Korea, published a report on thousands of North Korean nationals employed in industries around the world [13].
For a company hiring remote developers, the two programs converge at one point: the candidate pipeline. One set of applicants is trying to get hired. Another set is trying to get a developer to run something during the interview [4][6].
What to watch
- Whether Japanese prosecutors bring further cases against enablers after the first laptop farm dismantlement, and whether they name the recruiting services used.
- Whether sanctions designations follow now that four governments have named the 313 General Bureau of the Munitions Industry Department.
- Whether the Multilateral Sanctions Monitoring Team's next report names the employers that hired North Korean nationals.