A joint advisory from authorities in Japan, the United States, Australia and Germany has warned that the North Korean hacking group, tracked as WaterPlum, compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026. The attackers also stole cryptocurrency from more than 7,000 wallets and transferred about $10.7 million worth of cryptocurrency to North Korea.
WaterPlum is linked to the long-running “Contagious Interview” campaign, which targets job seekers through fake recruitment offers and technical interviews. The attackers often pretend to represent legitimate artificial intelligence, cryptocurrency or NFT firms and use recruiting and freelance platforms to contact victims.
During fake interviews or coding tests, victims may be asked to download software projects, fix supposed video-conferencing problems or run code on their computers. The files can contain malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
Once compromising the device, the attackers can steal browser passwords, cryptocurrency private keys and seed phrases, clipboard data, documents and keystrokes. Threat actors can also take screenshots and use the compromised computer to gain access to an employer's or client's network, potentially allowing them to steal sensitive information or conduct espionage.
The advisory also links WaterPlum to North Korea's fraudulent remote IT-worker operations. Authorities say that some of the same actors have worked as remote developers and that the groups have used the same IP addresses. Stolen identity documents from WaterPlum victims may also be reused by North Korean IT workers to obtain jobs under false identities.
Authorities say that some of the suspected workers have used AI face-swapping software during online job interviews. In some cases, the camera was then turned off, ostensibly because of network problems. Japanese authorities also reported dismantling a North Korean IT-worker “laptop farm” in Japan, where evidence showed that several hundred million yen had been transferred overseas.
The FBI and Japanese police assess that the WaterPlum threat actors and some North Korean IT workers operate under North Korea's 313 General Bureau, which is associated with the country's weapons research and production system.
Organizations are recommended to carefully verify applicants' identities, locations and qualifications and to limit employees' access to only the systems and data they need. Developers are also advised not to run unfamiliar code outside a secure sandbox and to inspect downloaded projects for commands that could retrieve additional malware.