North Korean WaterPlum campaign infected 30,000 devices, stole $10.7M in crypto via fake job interviews, say international agencies

Joint advisory from Japan, US, Australia, Germany reveals persistent RATs and malware families used in 'Contagious Interview' campaign

By LineZotpaper
Published
Updated
Read Time2 min
Sources3 outlets
International law enforcement agencies have issued a joint advisory detailing the scale and methods of the North Korean hacking group WaterPlum, which infected over 30,000 devices across 100 countries and stole at least $10.7 million in cryptocurrency through fake job interviews. The advisory, released by authorities in Japan, the United States, Australia, and Germany, reveals specific malware families and warns that compromised devices may provide ongoing access to victims' future employers, posing a persistent threat to corporate networks.

The WaterPlum threat group, linked to the long-running "Contagious Interview" campaign, has been active since at least December 2025, according to the joint advisory. The attackers impersonate recruiters from legitimate AI, cryptocurrency, and NFT companies, or use freelance platforms to approach job seekers. During fake interviews and coding tests, victims are instructed to download projects or execute code, which installs malware on their devices.

"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," the advisory states. "WaterPlum actors have transferred 1.7 billion Japanese yen (equivalent to $10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."

The advisory identifies several malware families used in the operations: BeaverTail (JavaScript malware in npm packages), InvisibleFerret (Python-based backdoor), OtterCookie (JavaScript remote-access trojan and information stealer), OtterCandy (combined RAT capabilities), and StoatWaffle (modular Node.js malware delivered through malicious Visual Studio Code projects).

Once implanted, these tools provide persistent remote access, allowing attackers to steal credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents long after the fake interview ends. The compromised machine may later serve as a springboard into the victim's legitimate employer's network. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory warns.

The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western companies, a scheme researchers estimate nets the regime upwards of $500 million annually via roughly 100,000 fraudulent workers. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume credentials have been compromised.

§

Analysis

Why This Matters

  • The campaign directly targets job seekers in tech, a vulnerable population, and the stolen credentials can be leveraged against future employers, amplifying the damage.
  • The $10.7M stolen represents direct funding for North Korea's weapons programs, highlighting the real-world consequences of cybercrime.
  • International coordination (Japan, US, Australia, Germany) signals growing awareness and a need for employer vigilance in hiring practices.

Background

North Korean cyber actors have long used financially motivated attacks to generate revenue for the regime, evading international sanctions. The "Contagious Interview" campaign has been active for years, initially targeting cryptocurrency and blockchain workers. The WaterPlum group represents a more sophisticated iteration, using multiple malware families and exploiting the remote-work environment. The stolen crypto is moved through mixers and exchanges, often ending up in North Korean-controlled wallets. In parallel, North Korea operates a vast network of fake IT workers infiltrating Western companies, a scheme that has been extensively documented by security researchers.

Key Perspectives

Law enforcement agencies (Japan, US, Australia, Germany): They warn that the campaign is ongoing and advise organizations to verify the identity of job applicants, avoid executing untrusted code during interviews, and monitor for signs of compromise. The advisory provides technical indicators and recommended mitigations. Victims (job seekers and their future employers): Job seekers are unwittingly used as entry points into corporate systems. Once hired, their compromised machines can remain backdoored for months, risking intellectual property and client data. North Korean regime: The operation serves a dual purpose: direct theft of cryptocurrency and acquisition of stolen identities to place more fake IT workers, creating a self-reinforcing revenue cycle that funds weapons development.

What to Watch

  • Whether other countries or tech companies adopt the advisory's recommended screening measures for remote job applicants.
  • Future reports of North Korean IT worker infiltrations that may use stolen identities from WaterPlum victims.
  • Potential sanctions or law enforcement actions targeting cryptocurrency exchanges identified in the laundering chain.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.