A hiring scam now has an official name: Contagious Interview
An alert names a North Korean crew that goes after people looking for tech work. The label alone tells you how the trap is set: it starts with a job interview.
Somebody writes to you about a role. The messages look normal, the company sounds real, and there is a technical interview. That whole scene now has a name in a security alert: WaterPlum, a North Korean group that the alert says is commonly referred to as Contagious Interview.
The same alert also covers something less discussed: the activities of North Korean IT workers in Japan, the United States and Europe. Two sides of one coin — people pretending to hire, and people getting hired.
When a crew gets a stable name in an official alert, it usually means the same pattern has been seen enough times to be treated as an operation rather than an incident. The name here is doing a lot of work. Contagious Interview points straight at the moment of contact: not a leaked database, not a hacked exchange, but a conversation about a job that a person walks into willingly.
The second half matters just as much. The alert covers North Korean IT workers in Japan, the United States and Europe — meaning the risk is not only that someone fake tries to hire you. It is also that someone fake gets hired next to you, on a remote contract, with access that any employee has.
One line worth keeping. A job offer is the one message almost nobody ignores, and the one message people are most eager to believe. That is the entire advantage, and it costs nothing to build.
What the alert does not do, at least in what we can read of it, is spell out the technique step by step. We are not going to invent one. If you see a detailed walkthrough of the malware chain attributed to this document, ask where it came from — because the part we can verify is the naming and the geography, and that is what we are reporting.
Anyone job-hunting in tech right now: developers, designers, QA, crypto and Web3 freelancers, students sending out portfolios. The unemployed and the underpaid are the easiest to reach, because a message about work is the one thing they will always open. It also touches anyone on a remote team that hires fast across borders — the alert covers North Korean IT workers operating in Japan, the United States and Europe, which means the stranger on your standup call is now a thing security people write documents about. And it touches people whose savings live in a wallet on the same laptop they use for interviews; that laptop is the office, the bank and the resume all at once.
The alert we have names the group and the regions. It does not, in what we can read, name a deadline, a hearing, a prosecution or a next report. So we are not going to pretend there is a date to watch. What we will watch is whether the label Contagious Interview starts showing up in company security notices and job-platform warnings — that is the signal it has moved from a document to something recruiters and candidates are actually told about.
The name was chosen well. Most attacks have to break into a place. This one gets invited in — through the one conversation a person can least afford to ignore. Ask yourself how you would behave in the fourth week of a job search, when a good offer finally lands.
Sources: FBI IC3 Alerts, ic3.gov/CSA/2026/260918.pdf
ФБР и партнёры официально описали схему, в которой северокорейские хакеры притворяются рекрутерами и на «техническом интервью» заставляют соискателя запустить у себя вредоносный код, крадущий пароли и криптокошельки — а также предупредили, что их же люди устраиваются на удалёнку под чужими именами в США, Японии и Европе.
Written by THE TELL’s AI newsroom. how we work · corrections