WaterPlum and some North Korean fraudulent remote IT workers are assessed to operate under the same 313 General Bureau within the Munitions Industry Department. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices in more than 100 countries and compromised funds or credentials associated w...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How are North Korea’s WaterPlum (Contagious Interview) hacking group and its fraudulent remote IT-worker scheme connected under the 313 Gene. Article summary: WaterPlum and the fraudulent remote-IT-worker operation are assessed as complementary North Korean revenue and access operations: both are linked to the 313 General Bureau, an entity under the Munitions Industry Departme. Topic tags: general, general web, government. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake n
WaterPlum—also known as Contagious Interview—and North Korea’s fraudulent remote IT-worker activity are linked by more than their use of employment-themed deception. Japanese and U.S. authorities assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau, which sits within the Munitions Industry Department subordinate to the Central Committee of the Workers’ Party of Korea.5
The two activities serve different but complementary purposes. WaterPlum uses fake recruiting to compromise people seeking work, steal sensitive information, and take cryptocurrency. The IT-worker scheme uses false identities and location concealment to obtain legitimate remote jobs, producing revenue and potentially placing an insider within a target organization.5
17
The September 18 joint cybersecurity advisory was issued by seven agencies across Japan, the United States, Australia, and Germany:1
Their assessment names the cyber actor group WaterPlum and notes its association with the campaign commonly called Contagious Interview.1
WaterPlum impersonated recruiters or prospective employers and targeted IT professionals, including web designers, engineers, and people working in cryptocurrency, blockchain, and Web3 fields.1
4
The lures were designed to look like normal steps in a technical hiring process. A target might receive a purported coding task or be asked during a video interview to install a supposed conferencing fix. Instead, these files or instructions delivered malware to the job seeker’s device.1
5
That approach turns a routine recruitment interaction into an initial-access channel. Rather than attempting to breach a company directly, the operators exploit the trust and urgency surrounding a promising job opportunity.
The advisory assesses that, from December 2025 through July 2026, WaterPlum infected at least 30,000 devices in more than 100 countries. Funds or account credentials associated with more than 7,000 cryptocurrency wallets were compromised, and the operation received approximately $10.71 million in cryptocurrency.1
4
These figures describe a campaign that combined broad targeting of technical professionals with a focused financial objective. The theft of credentials is particularly consequential because compromised accounts can enable further fraud even when an immediate transfer is not possible.
The fraudulent IT-worker scheme relies on operatives concealing their real identity and location to win remote contracts. Government guidance warns that North Korean IT workers have used third-party proxies and facilitators, while companies are urged to strengthen identity verification and detect suspicious account activity.17
The relationship to WaterPlum is organizational and strategic, according to the NPA and FBI assessment—not necessarily proof that every malware victim becomes part of the worker scheme or that every fraudulent worker participates in WaterPlum operations.5 The practical connection is that both exploit the remote-work ecosystem:
One produces direct compromise and cryptocurrency theft; the other can create a longer-term revenue stream and insider-access risk.
Reporting on New Zealand’s National Cyber Security Centre described a large New Zealand business that hired a remote IT contractor using a false identity. When the company became suspicious, the contractor threatened to release sensitive information.18
The case is a reminder that identity fraud is not only a payroll or compliance issue. A fraudulently hired worker may gain access to corporate systems, data, credentials, or company-issued equipment before the deception is discovered.
Recruiting, HR, IT, security, and procurement teams should coordinate controls for remote technical roles. U.S. government guidance specifically calls for stronger identity verification, including strict review of identification documents and in-person interviews where appropriate, alongside systems that flag anomalous information in accounts.17
Practical measures include:
WaterPlum demonstrates that a job interview can be used as a malware-delivery mechanism. The related fraudulent IT-worker threat demonstrates that hiring can also be an intrusion path. The shared 313 General Bureau attribution makes the central defensive point clear: organizations need to secure both sides of the employment process—protecting job seekers from fake recruiters and protecting employers from identity-based infiltration.5
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
WaterPlum and some North Korean fraudulent remote IT workers are assessed to operate under the same 313 General Bureau within the Munitions Industry Department.
WaterPlum and some North Korean fraudulent remote IT workers are assessed to operate under the same 313 General Bureau within the Munitions Industry Department. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices in more than 100 countries and compromised funds or credentials associated with over 7,000 cryptocurrency wallets, with roughly $10.71 mi...
For employers, the shared lesson is to treat recruiting and remote onboarding as security controls: independently verify identities and investigate suspicious location, device, and access patterns.[17]