A joint advisory from agencies in Japan, the US, Australia, and Germany says North Korea's WaterPlum group infected at least 30,000 devices in more than 100 countries and took funds or credentials from over 7,000 cryptocurrency wallets.

 

What happened

WaterPlum, commonly called Contagious Interview, ran its campaign from around December 2025 to July 2026. At least JPY1.7bn ($10.7 million) in cryptocurrency went to North Korea.

The actors posed as employers, often impersonating AI, cryptocurrency, or NFT companies. They recruited developers through social media, job boards, and freelance marketplaces, and mainly targeted web designers, engineers, and cryptocurrency and Web3 specialists.

During technical interviews or coding assignments, the actors told victims to download and run files hosted on developer platforms and code repositories. Those files carried malicious code containing BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware.

Once inside, the actors used remote access trojans and infostealers to take browser credentials, keystrokes, screenshots, wallet private keys and seed phrases, and ID documents. The infections also provided the attackers with a potential path into the victims’ employers’ networks.

 

What was said

The joint advisory ties WaterPlum to North Korea's IT worker scheme. Japanese authorities said they identified and dismantled a laptop farm in Japan for the first time. Their investigations suggest North Korean IT workers moved several hundred million yen abroad, including cryptocurrency. The agencies urged firms to limit contractors' access to source code and credentials, verify applicants' identities, and consider risks from downstream subcontractors.

 

By the numbers

  • At least 30,000 devices infected in more than 100 countries.
  • Funds or credentials taken from over 7,000 cryptocurrency wallets.
  • At least JPY1.7bn ($10.7 million) in cryptocurrency transferred to North Korea.
  • Activity ran from around December 2025 to July 2026.
  • Several hundred million yen moved abroad by North Korean IT workers, including cryptocurrency.

 

In the know

Laptop farms are sites, often an enabler's home, where North Korean workers remotely set up and control employment computers. These enablers supply identity documents, bank accounts, and virtual private servers to hide where the workers are.

A VS Code task file is a configuration file that tells the editor to run commands automatically. Attackers abuse the "folderOpen" setting so a developer's own tools run the malware the moment a project opens.

 

Why it matters

WaterPlum targeted developers with the very tasks they expect during a job search, such as coding assignments and technical interviews. A victim who runs one file can hand over wallet keys and seed phrases and give the actors a route into their employer.

The advisory also shows that one threat can play two roles. Because some WaterPlum actors work as IT workers, the same people who infect developers' devices may also apply for jobs at target companies, using the same IP addresses. Some of those workers extorted employers, leaked source code, and kicked a client's website offline.

 

The bottom line

WaterPlum shows that job offers, hiring processes, and even trusted code repositories are now targets. Organizations should limit contractors' access to source code and credentials and weigh the risks from downstream subcontractors. Additionally, developers should open unknown projects in Restricted Mode and check any tasks.json file before running it.

 

FAQs

What is an infostealer?

An infostealer is malware that collects saved passwords, browser data, and other sensitive files from an infected device and sends them to the attacker.

 

What is a remote access trojan?

A remote access trojan (RAT) is malware that gives an attacker hidden control over a victim's computer from a distance.

 

What is a software supply chain attack?

A software supply chain attack compromises trusted code or updates, so victims install malware without realizing it.