Breaking
Cyber CrimeDeveloping Story

Fake Job Interviews Fuel North Korea Crypto Theft

A joint advisory links WaterPlum's developer-targeting campaign to over $10.7m in stolen cryptocurrency and 30,000 infected devices worldwide.

··3 hours ago·6 min read
black flat screen computer monitor
Photo by Riku Lu on Unsplash

North Korean operatives turned the job hunt itself into an attack surface, using fake technical interviews and malicious coding assignments to reach tens of thousands of machines and drain cryptocurrency wallets across the globe. The scale of that campaign, outlined in a new multinational advisory, places it among the more expansive developer-targeting operations attributed to Pyongyang in recent years.

The group tracked as WaterPlum, better known as Contagious Interview, compromised at least 30,000 devices in more than 100 countries and took funds or credentials from over 7,000 cryptocurrency wallets, according to the joint advisory. Japan's National Police Agency (NPA) and National Cybersecurity Office, the FBI, the Defense Department's Cyber Crime Center, Australia's ACSC, and Germany's BND and BfV jointly attributed the activity to North Korea.

At least JPY1.7bn ($10.7m) in cryptocurrency was transferred to North Korea during the operation, which the agencies said ran from roughly December 2025 to July 2026.

Fake Interviews, Real Malware

The mechanics of the campaign revolve around a deceptively simple premise: pose as a hiring manager at a fast-moving technology company and persuade talented developers to run code as part of the application process. WaterPlum actors often impersonated AI, cryptocurrency, or NFT companies, recruiting through social media, job boards, and freelance marketplaces.

Web designers, engineers, and cryptocurrency and Web3 specialists were the main targets. During technical interviews or coding assignments, victims were instructed to download and execute files hosted on developer platforms and code repositories — a request that blends seamlessly into the normal rhythm of a technical hiring pipeline.

The actors seeded malicious NPM packages carrying BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. Because these packages sat in the same ecosystems developers already trust, the malicious code could execute the moment a victim followed the interview instructions.

Blockchain Projects as a Delivery Vehicle

One of the more unusual delivery methods involved StoatWaffle, which arrives inside blockchain-themed Visual Studio Code (VSC) projects. Once a victim opens the project and trusts the folder, malicious code runs automatically — no additional prompting required.

To reduce exposure to this technique, the agencies advised opening unknown projects in Restricted Mode and checking any tasks.json file before running it. The recommendation reflects how developer tooling has become an attack surface in its own right: folder trust in VSC is a convenience feature, and it can be weaponized when a project originates from an untrusted source.

After establishing a foothold, the actors deployed remote access trojans and infostealers to harvest browser credentials, keystrokes, screenshots, wallet private keys and seed phrases, and identity documents. Those infections also gave the attackers a path into the victims' employers, turning a single compromised laptop into a potential entry point for corporate networks.

WaterPlum and IT Workers Overlap

The advisory draws a close connection between WaterPlum and North Korea's broader IT worker scheme, stating that some WaterPlum actors also work as North Korean IT workers. The two operations used the same IP addresses to reach laptop farms and crowdsourcing services and to apply for jobs at a Japanese cryptocurrency exchange.

Laptop farms are sites, often an enabler's home, where employment computers are set up and controlled remotely by North Korean workers. Enablers supply identity documents, bank accounts, and virtual private servers to obscure the workers' true location.

Japanese authorities identified and dismantled a laptop farm in Japan for the first time, the advisory said. Their investigations suggest North Korean IT workers moved several hundred million yen abroad, including cryptocurrency.

Some workers turned destructive once hired. One extorted a company over payment and published its source code, while another defaced a client's website and took it offline.

Inside the 313 General Bureau

The NPA and FBI assessed that WaterPlum and some North Korean IT workers operate under the 313 General Bureau, part of the Munitions Industry Department, which is subordinate to the Central Committee of the Workers Party of Korea. That attribution ties a financially motivated criminal operation to the country's defense and political apparatus.

The finding reinforces the view that North Korea's cyber theft operations are not isolated rogue activities but organized efforts with institutional backing. The overlap between espionage-adjacent structures and revenue-generating IT worker fraud suggests the same personnel and infrastructure support multiple missions.

For defenders, the practical implication is that a single indicator — a suspicious IP address, for instance — may connect to both a cryptocurrency heist and an employment fraud scheme. Pivoting on such indicators during an investigation could reveal connections that a narrow, incident-specific view would miss.

A Global Advisory, a Global Threat

The advisory carries weight because of the number of agencies that signed it. Japan's National Police Agency and National Cybersecurity Office, the FBI, the Defense Department's Cyber Crime Center, Australia's ACSC, and Germany's BND and BfV all put their names to the assessment — a level of coordination that signals the activity is viewed as a multinational problem rather than a regional nuisance.

The geographic spread of victims, spanning more than 100 countries, underscores the reach of the campaign. Cryptocurrency thefts are borderless by nature: funds can move across exchanges and wallets in minutes, complicating recovery even when the theft is detected quickly.

Japan's role in the investigation is notable. Authorities there identified and dismantled a laptop farm for the first time, and the financial flows they traced include several hundred million yen moved abroad. That combination of physical infrastructure and digital theft highlights how the operation blends real-world enablers with online intrusion.

What Companies Should Watch For

The agencies urged firms to limit contractors' access to source code and credentials, verify applicants' identities, and consider risks from downstream subcontractors. Each of those recommendations maps directly to a weakness the campaign exploited.

Blind trust in a candidate's technical setup is one of the weakest links. A coding assignment that asks a developer to run an untrusted repository is now a potential malware delivery mechanism, and hiring managers are rarely trained to treat it that way.

Contractor access is another soft spot. When external developers are given broad permissions to source code and credentials, a single compromised machine can expose far more than the project at hand. The advisory's guidance to limit that access is a straightforward mitigation that many organizations may not have implemented.

Identity verification matters as well, particularly when remote hiring spans borders. The campaign's use of laptop farms and enabler-supplied documents shows that identity claims in a hiring process can be fabricated at scale.

Not the First Warning

The advisory builds on prior warnings about the Contagious Interview campaign. Earlier reporting described the same pattern of fake coding tasks used to steal cryptocurrency, and separate research tied new malware loaders to the group's evolving toolkit.

The addition of StoatWaffle and other payloads shows the operation has not stood still. Malicious NPM packages, blockchain-themed VSC projects, and infostealers are all pieces of a toolkit that continues to be refined based on what makes developers click, download, and run.

For security teams, the takeaway is that the threat is not confined to a single vector or a single region. The same group appears to be running recruitment fraud, cryptocurrency theft, and destructive retaliation — sometimes all at once.

Implications Beyond the Headlines

The numbers in this advisory are large, but the operational lesson is about trust. Developers are trained to be helpful during interviews and to run code when asked. Attackers have turned that professional courtesy into a delivery mechanism.

Organizations that hire remotely, especially in Web3 and cryptocurrency, may want to treat every incoming coding assignment as potentially hostile. Sandboxing unknown projects, restricting folder trust in development environments, and limiting what a new contractor can touch are practical steps that reduce exposure.

The link between WaterPlum and the IT worker scheme also complicates the picture for employers. A candidate who passes a technical interview might still be part of an operation that generates revenue for a foreign government — or, in some documented cases, might turn destructive after being hired.

For the cryptocurrency industry, the theft of wallet private keys and seed phrases remains difficult to reverse. Once funds move, recovery depends on exchanges and law enforcement coordinating across jurisdictions, a process that is rarely fast enough.

The broader signal is that recruitment pipelines and developer tooling have become first-class attack surfaces. Defenders who treat hiring and onboarding as a security boundary — not just an HR process — will be better positioned to spot the fake interview before the malicious code runs.

#north korea#waterplum#cryptocurrency theft#fake job interviews#malware#cyber espionage

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories