On 18 September, Australia's cyber security agency issued an advisory on North Korean campaigns — tracked as WaterPlum, and widely known as Contagious Interview — that target IT professionals through fake recruitment approaches delivering malware. It is worth being blunt about what this means: the phishing lure most likely to compromise your business right now is not an invoice or a parcel notification aimed at everyone. It is a flattering job opportunity aimed at the two or three most technically privileged people you employ.
How the lure works
The pattern the advisory describes has been refined over several years and it works because every step mimics legitimate tech recruiting:
- The approach. A recruiter profile — polished, plausible, sometimes months old — contacts a developer or IT admin about a well-paid role, typically remote, often crypto- or fintech-flavoured.
- The interview. Real calls, real technical questions. The process feels legitimate because most of it is theatre performed properly.
- The payload. The candidate is asked to complete a coding challenge: clone this repository, run this project, install this video-call tool to continue. The repo or installer carries the malware. The victim runs it themselves, on the machine they use for work, with the permissions a developer has.
- The harvest. Credentials, session tokens, SSH keys, cloud access, crypto wallets — whatever the compromised profession keeps within reach.
Notice what is absent: no malicious attachment from a stranger, no misspelled domain, none of the classic tells from the warning signs of phishing. The target performs the compromise voluntarily, as a career step. It is the same psychology we unpack in social engineering tactics in 2026 — attackers do not break trust, they construct it.
Why IT staff, specifically
Because the return is asymmetric. A developer's laptop holds repository access, deployment credentials and often production database reach. One successful fake interview equals what months of conventional phishing might achieve. And technical staff are, inconveniently, often the most confident that they would never fall for phishing — confidence calibrated against invoice scams, not against a three-round interview with a working video call.
What to tell your technical team this week
Make it a five-minute briefing, not a policy document:
- Job-hunting is fine; running code is the line. Never run a take-home challenge, recruiter-supplied repo or "interview platform" installer on a work machine. Personal job search, personal device, ideally a disposable VM.
- Coding challenges from unknown parties get read, not run. If a role requires executing their project to proceed, that is the tell.
- Verify the recruiter through the company, not the profile. A real hiring company can confirm a real process through its own careers channel.
- Reporting an approach is safe. Staff hide job-hunting from employers, which is exactly the shadow this campaign lives in. Make clear that reporting a suspicious approach carries zero career consequence — the same no-blame reporting culture that makes all phishing training for employees actually work.
For the business
- Developer machines deserve tighter egress monitoring and separated credentials — assume one gets compromised and limit what that means
- Keep production access behind MFA and short-lived tokens, not long-lived keys sitting in dotfiles
- Add a fake-recruiter scenario to your awareness programme; generic phishing modules do not cover it
This campaign is aimed at people, not systems — which makes trained people the control. SecureAZ's NZ/AU awareness modules and simulations cover social engineering well beyond the invoice scam, with the reporting culture to match. Start a free 45-day trial.