The U.S. Department of Defense Cyber Crime Center (DC3), Federal Bureau of Investigation (FBI), Japan’s National Police Agency (NPA) and National Cybersecurity Office (NCO), along with Australian and German cybersecurity and intelligence partners, have released a joint advisory detailing malicious activity associated with the North Korean “WaterPlum” cyber actor group, commonly referred to as “Contagious Interview.”
WaterPlum actors pose as prospective employers and recruiters, targeting software developers and IT professionals with attractive job opportunities. The group has impersonated legitimate artificial intelligence, cryptocurrency, and non-fungible token companies and has also used recruiting services to reach potential victims.
Why This Matters
The campaign is designed to turn a routine part of the hiring process into an opportunity for compromise.
WaterPlum actors recruit job seekers through social media, online job platforms, gig-work services, and freelance marketplaces. During technical interviews or coding assignments, victims may be instructed to download files, troubleshoot software, or execute code that contains malware. Once installed, the malware can provide remote access to the victim’s system and enable the theft of credentials, sensitive information, and cryptocurrency.
Successful infections may also create opportunities for actors to access organizations connected to targeted developers, potentially enabling additional lateral movement, intellectual property theft, and exposure of corporate information.
WaterPlum Activity at a Glance
According to the advisory, from approximately December 2025 through July 2026:
-
At least 30,000 devices were compromised in more than 100 countries.
- More than 7,000 cryptocurrency wallets had funds or account credentials transferred.
- At least 1.7 billion Japanese yen — approximately $10.71 million USD — in cryptocurrency was exfiltrated from victims on behalf of the DPRK.
- Primary targets included web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.
How the Attack Can Begin
A prospective employer or recruiter may appear legitimate and invite a candidate to participate in a virtual technical interview or coding exercise. The candidate may then be asked to download a project, package, or file from a developer platform or code repository.
The advisory identifies malicious NPM packages and malware families associated with this activity, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The diagram on page 3 of the advisory illustrates how a seemingly routine developer assignment can lead from malicious code execution to credential and cryptocurrency theft.
Reduce Your Risk
IT professionals, developers, recruiters, and organizations should use additional caution when interacting with unfamiliar recruiters, technical assignments, and code repositories.
The joint advisory recommends several protective measures, including:
- Avoid executing code received from untrusted third parties on systems containing sensitive data or cryptocurrency assets.
- Use a sandbox or virtual machine when evaluating unknown code.
- Be cautious of unfamiliar Visual Studio Code projects and consider opening them in Restricted Mode.
- Review .vscode/tasks.json files for commands that attempt to download or execute additional files.
- Disconnect a device from the internet if compromise is suspected.
- Organizations should consider Endpoint Detection and Response (EDR) capabilities to monitor malicious behavior.
- During recruiting, validate candidate information, claimed skills, certifications, contact information, and other inconsistencies that may warrant additional verification.
Read the Full Joint Advisory
|