The WaterPlum threat group, linked to the long-running "Contagious Interview" campaign, has been active since at least December 2025, according to the joint advisory. The attackers impersonate recruiters from legitimate AI, cryptocurrency, and NFT companies, or use freelance platforms to approach job seekers. During fake interviews and coding tests, victims are instructed to download projects or execute code, which installs malware on their devices.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," the advisory states. "WaterPlum actors have transferred 1.7 billion Japanese yen (equivalent to $10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."
The advisory identifies several malware families used in the operations: BeaverTail (JavaScript malware in npm packages), InvisibleFerret (Python-based backdoor), OtterCookie (JavaScript remote-access trojan and information stealer), OtterCandy (combined RAT capabilities), and StoatWaffle (modular Node.js malware delivered through malicious Visual Studio Code projects).
Once implanted, these tools provide persistent remote access, allowing attackers to steal credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents long after the fake interview ends. The compromised machine may later serve as a springboard into the victim's legitimate employer's network. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory warns.
The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western companies, a scheme researchers estimate nets the regime upwards of $500 million annually via roughly 100,000 fraudulent workers. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume credentials have been compromised.