Law enforcement agencies from Japan, the United States, Australia, and Germany warned of a wide-ranging campaign carried out by the North Korean hacking group WaterPlum after investigations showed that at least 30,000 devices in more than 100 countries were compromised between December 2025 and July 2026. According to the joint warning, the group extracted funds or credentials from more than 7,000 cryptocurrency wallets and transferred assets worth 1.7 billion Japanese yen, or approximately $10.71 million, to North Korea.
WaterPlum is linked to a years-long campaign known as Contagious Interview, which targets job seekers by impersonating legitimate companies in the fields of artificial intelligence, cryptocurrency, and non-fungible tokens, or through recruitment and freelance-work platforms. During fake interviews or coding tests, victims are asked to download projects, troubleshoot alleged problems in video conferences, or run code that infects their devices.
Multiple Malware Families and a Single Attack Path
The warning linked WaterPlum’s operations to several malware families, including BeaverTail hidden inside npm packages, InvisibleFerret, which functions as a Python-based backdoor, and OtterCookie, classified as a remote-access trojan and information stealer, in addition to OtterCandy and StoatWaffle. StoatWaffle is delivered through malicious Visual Studio Code projects, using configuration files to execute code after the folder is opened and trusted.
After compromising a device, the group attempts to steal browser credentials, clipboard contents, keystrokes, private keys, and recovery phrases for cryptocurrency wallets, along with documents and screenshots. It may use initial access to move into employers’ or clients’ networks, expanding the potential impact to intellectual-property theft and espionage.
Link to Fake Technology-Worker Operations
Investigating agencies also link WaterPlum to operations involving North Korean technology workers who fraudulently obtain remote jobs. The warning stated that some WaterPlum members work as remote developers and that the two groups used the same IP addresses. Stolen identity documents from WaterPlum victims are also reused to impersonate them and apply for jobs.
The investigation indicated the use of AI face-swapping software during interviews, followed by turning off the camera and blaming network problems. The FBI and Japanese police estimate that WaterPlum and some North Korean technology workers operate under the supervision of Bureau 313, which is affiliated with the Ministry of Munitions Industry and responsible for weapons research and production. The National Police Agency of Japan also announced that it had identified and dismantled a “laptop farm” facility linked to North Korean technology workers, finding evidence that hundreds of millions of yen had been transferred overseas.
What Does This Mean for Organizations Hiring Developers?
The facts show that a job interview and coding test may constitute an entry point into an organization’s environment, rather than merely a stage for evaluating a candidate. Agencies therefore recommend carefully verifying an applicant’s identity, location, and qualifications, and limiting an employee’s access to the systems and data necessary for their work.
Developers, meanwhile, should avoid running unknown code outside an isolated environment and inspect files and projects for commands that retrieve additional payloads. The scope of the campaign and its reported losses remain tied to what agencies have been able to track, so the figures provided do not establish the full scale of the activity, but they confirm that recruitment and development channels have become part of the financial and espionage attack surface.