A North Korean hacking operation posing as technology recruiters has infected at least 30,000 devices across more than 100 countries, according to a joint warning from international security agencies. The campaign, tracked as WaterPlum and commonly known as Contagious Interview, targets software developers and other IT professionals with fake employment opportunities.
Authorities say the attacks took place on a large scale between December 2025 and July 2026. Victims have been identified in the United States, Japan, Europe and other regions, with web developers, engineers and specialists working with cryptocurrency, blockchain and Web3 technologies among the main targets.
WaterPlum begins its attacks by approaching potential victims through social media, recruitment websites, freelance marketplaces, and other online platforms. The hackers pose as recruiters or representatives of legitimate companies, frequently using supposed job openings at AI, cryptocurrency, and NFT businesses to attract developers looking for work.
Once contact is established, victims are invited to technical interviews or asked to complete coding assignments. The attackers then convince them to download projects from developer platforms and code repositories, or claim that software must be installed to resolve problems with a video interview.
The downloaded files contain malware that gives WaterPlum access to the victim’s computer. Authorities have connected several malware families to the campaign, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, with different tools used to steal information and maintain remote access.
After compromising a device, the attackers search for valuable information stored on it. This can include browser passwords, clipboard contents, keystrokes, screenshots, files, and cryptocurrency wallet information such as private keys and recovery seed phrases.
The scale of the cryptocurrency theft has been substantial. Investigators say WaterPlum obtained funds or account credentials from more than 7,000 cryptocurrency wallets and transferred approximately 1.7 billion Japanese yen, equivalent to about $10.71 million, in cryptocurrency assets to North Korea.
The infections can also create risks for companies employing the targeted developers. Once a developer’s computer has been compromised, the attackers may attempt to move into connected corporate environments, potentially gaining access to intellectual property, internal systems, and other sensitive business information.
Authorities have also uncovered links between WaterPlum and North Korea’s fraudulent remote IT worker operations. Some people involved in WaterPlum activity are believed to also perform legitimate-looking web development work for foreign clients while hiding their real identities and locations.
Information stolen during the hacking campaign can support those operations. Investigators warn that identity documents taken from infected computers, including passport and driver’s license images, may later be reused by North Korean IT workers to impersonate other people when applying for remote jobs.
The hackers have adopted additional techniques to make fake applicants appear more convincing. Investigators observed WaterPlum operators using AI face-swapping software during online interviews before switching off their cameras and blaming network problems for continuing without video.
The joint investigation also uncovered infrastructure used to disguise where North Korean workers were actually located. Authorities say intermediaries in several countries have operated “laptop farms,” where computers physically located in another country are remotely controlled by North Korean workers to make their activity appear local.
Japanese authorities recently dismantled what they described as the country’s first identified North Korean IT worker laptop farm. Investigators found evidence that several hundred million yen had been transferred overseas through activity associated with the operation.
The FBI and Japan’s National Police Agency assess that WaterPlum operators and some North Korean IT workers operate under the 313 General Bureau, part of North Korea’s Munitions Industry Department. The latest advisory connects the fake recruitment attacks, cryptocurrency theft, and fraudulent remote employment operations as overlapping parts of a broader effort to obtain money and sensitive information from foreign targets.
