The Australian Signals Directorate has issued an alert about the North Korean WaterPlum cyber actor group, which targets IT professionals to steal cryptocurrency and sensitive information.
Background
The North Korean WaterPlum cyber actor group, commonly referred to as Contagious Interview, conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. According to the Australian Signals Directorate, WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities.
Tactics, Techniques, and Procedures (TTPs)
WaterPlum actors recruit job seekers internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces. During the recruitment cycle, WaterPlum actors require job seekers to participate in technical online virtual interviews or complete technical coding assignments. The actors then instruct job seekers to download and execute malicious files, hosted on multiple online collaboration software developer platforms and code repositories, to complete a coding assignment or troubleshoot an error in the online video conferencing platform.
Mitigation Measures
To protect against WaterPlum cyber attacks, IT professionals and businesses should be cautious when participating in online job interviews or freelance work. They should verify the identity of potential employers and be wary of requests to download and execute unknown files. Additionally, they should implement robust security controls, such as multi-factor authentication and regular software updates, to prevent malware infections and protect sensitive information.
Practical Response
Australian healthcare organisations and Melbourne businesses should review their cybersecurity protocols to ensure they are protected against WaterPlum cyber attacks. This includes implementing robust security controls, such as multi-factor authentication and regular software updates, and educating IT staff on the risks associated with online job interviews and freelance work. By taking these precautions, organisations can reduce the risk of falling victim to WaterPlum cyber attacks and protect their sensitive information.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
