Joint Advisory Reveals Scale of DPRK Campaign
A joint law enforcement advisory from authorities in Japan, the United States, Australia, and Germany has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, transferring more than $10.7 million in stolen cryptocurrency to North Korea.
According to the advisory, WaterPlum actors moved 1.7 billion Japanese yen — roughly $10.71 million USD — in cryptocurrency assets to the Democratic People's Republic of Korea, drained from over 7,000 compromised cryptocurrency wallets.
The "Contagious Interview" Playbook
WaterPlum is linked to a long-running campaign tracked as Contagious Interview, which has previously used malicious npm packages to infect job seekers' devices. The group impersonates legitimate AI, cryptocurrency, and NFT companies, or poses as recruiters on freelance and job platforms, to draw in targets — primarily web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.
During fake interviews and coding tests, victims are instructed to:
- Download a "project" or take-home coding assignment
- Troubleshoot a supposed video-conferencing problem
- Execute code as part of a technical evaluation
Each of these steps is a delivery mechanism for malware.
Malware Arsenal
| Malware | Type | Function |
|---|---|---|
| BeaverTail | JavaScript | Concealed in malicious npm packages |
| InvisibleFerret | Python | Backdoor for persistent access |
| OtterCookie | JavaScript | Remote-access trojan and information stealer |
| OtterCandy | Hybrid | Combines OtterCookie and RAT capabilities |
| StoatWaffle | Node.js | Modular malware delivered via malicious VS Code project configs that auto-execute on folder trust |
Once installed, this toolkit harvests browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, documents, and periodic screenshots.
A State-Directed Operation
Authorities assess that WaterPlum actors, along with some North Korean IT workers operating abroad, function under North Korea's Munitions Industry Department. In a related development, police also shut down the country's first known domestic "laptop farm," where local facilitators hosted computers in their homes while North Korean operators controlled them remotely — posing as Japanese residents to win freelance contracts. Shared IP infrastructure tied the laptop farm directly to the WaterPlum hacking activity.
The official tally in this advisory dwarfs prior independent research: one researcher who spent 22 months inside the group's infrastructure had previously mapped only 1,640 victims across 57 countries — about 18 times smaller than the numbers now confirmed by law enforcement.
Protecting Against Fake Interview Attacks
- Never run code from an unsolicited "interview assignment" outside an isolated VM or sandboxed environment
- Verify recruiter identities independently through official company channels before proceeding with technical exercises
- Avoid granting "trust this workspace" prompts in VS Code or similar editors for unfamiliar repositories
- Isolate cryptocurrency wallets and seed phrases from general-purpose development machines
- Audit npm packages pulled in as part of take-home assignments before execution
- Treat "fix your video call" instructions during interviews as a major red flag