Advisory
Published 2026-09-18
Verified 2026-09-19

ACSC joint advisory: DPRK WaterPlum / Contagious Interview targets IT pros (crypto + laptop farms)

ASD’s ACSC (18 September 2026) republishes a joint advisory with Japan’s NPA/NCO, US FBI and DC3, and Germany’s BND/BfV on the North Korean “WaterPlum” cyber actor group (commonly Contagious Interview). Actors pose as employers (often fake AI, cryptocurrency, or NFT companies / recruiters) to target software developers and IT professionals, then deliver loaders leading to RATs and infostealers including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle variants. Advisory cites ≥30,000 infected devices in 100+ countries and credentials/funds stolen from >7,000 cryptocurrency wallets; ~¥1.7 billion JPY (~USD 10.71M) in crypto assessed transferred to DPRK. WaterPlum actors and some DPRK IT workers assessed under the 313 General Bureau (Munitions Industry Department). Japan dismantled a domestic “laptop farm” enabler; FBI continues US facilitation prosecutions. Audience: IT professionals and organisations that outsource/crowdsource development. No CVE. Primary: ACSC advisory page (joint determination).

Product
Threat actor WaterPlum / Contagious Interview (DPRK) — job-seeker / freelance IT targeting
Exploited in Australia?
unknown
Patch to
IT pros and hiring orgs: verify recruiter identity; do not run untrusted interview coding tools/loaders; isolate interview VMs; MFA on crypto wallets; review ACSC/joint TTP and mitigation sections; report laptop-farm facilitation

Primary: ACSC — WaterPlum / Contagious Interview joint advisory (18 Sep 2026) · Vendor: ACSC alerts and advisories index

australia identity ai