SlowMist|Sep 22, 2026 09:47
🇯🇵🇺🇸🇦🇺🇩🇪 On Sep 18, Japan’s NPA and National Cybersecurity Office, the U.S. FBI and DC3, Australia’s ASD/ACSC, and Germany’s BND and BfV jointly released a report on North Korea-linked #WaterPlum, also known as “Contagious Interview” .
SlowMist analyzed the report, examining the links between fake-job phishing, malware attacks, and “Laptop Farm” operations.
📄 Official report: https://www.npa.go.jp/bureau/cyber/pdf/20260918_j.pdf
🔎 What the report reveals
• Dec 2025–Jul 2026: 30,000+ computers infected across 100+ countries and regions
• Data from 7,000+ crypto wallets stolen; at least JPY 1.7B (~USD 10.71M) flowed into wallets controlled by WaterPlum
• Fake technical interviews can be used to deliver malware, steal credentials and wallet data, and enable further intrusion into corporate networks
• Japan disclosed its first Laptop Farm seizure and dismantling
👤 For individuals / freelancers
Don’t run unfamiliar interview code on machines holding wallets or sensitive work data. If an alert fires, disconnect from the internet first.
🏢 For hiring / outsourcing teams
Treat unusually broad résumés, crypto-only payment requests, and refusal to work on-site as security signals worth investigating.
📖 Full analysis: https://slowmist.medium.com/analysis-joint-report-by-japan-the-us-australia-and-germany-job-seeking-phishing-and-laptop-d98a57bdfc3f
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink