A multi-country advisory published September 18 attributes a long-running fake-recruitment operation to North Korea-linked actors tracked as WaterPlum, widely known as Contagious Interview. The operation infected at least 30,000 computers across more than 100 countries and compromised funds or credentials from over 7,000 cryptocurrency wallets, stealing at least ¥1.7 billion — about $10.71 million — between December 2025 and July 2026.
The advisory was issued jointly by Japan's National Police Agency and National Cybersecurity Office, the FBI, the U.S. Defense Department's Cyber Crime Center, and agencies in Australia and Germany. Japan's NPA published its own caution notice the same day, and the Australian Signals Directorate carries the full advisory. Japanese reporting puts the domestic dimension in context: the NPA says the campaign was behind thefts of cryptocurrency worth about ¥1.7 billion across more than 100 countries, including Japan, per The Japan Times.
How the Lures Worked
WaterPlum operators posed as recruiters or prospective employers representing legitimate cryptocurrency, AI and NFT companies, approaching targets through social networks, job platforms, freelance marketplaces and recruitment services, per the advisory as summarized by Crypto Adventure and BeInCrypto. Victims were invited to technical interviews or coding assessments, then instructed to download and execute files — framed as completing a coding task or fixing a video-conferencing problem.
The payloads include the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware families, delivered through malicious NPM packages, code repositories and Visual Studio Code projects. Once installed, the malware can capture browser credentials, clipboard contents, keystrokes and screenshots while specifically searching for cryptocurrency private keys and seed phrases. Remote-access tooling preserves access to infected machines and can provide a path into the networks of a victim's employer or clients.
The Attribution
The FBI and NPA assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which sits under the Central Committee of North Korea's Workers' Party. Investigators also found infrastructure overlap between the hacking operation and North Korean IT-worker schemes: the same IP addresses were used to access laptop farms, crowdsourcing services and applications for positions at a Japanese cryptocurrency exchange. Japanese authorities dismantled one such laptop farm after identifying computers remotely controlled from abroad.
What the Advisory Tells Victims to Do
The guidance is blunt about residual risk: removing detected malware does not guarantee that previously stored wallet information is safe. Users who suspect a device was compromised are advised to disconnect it from the internet, create a new wallet on a separate clean device, and move assets to new addresses backed by a newly generated recovery phrase. Authorities recommend a full operating-system reset for infected machines, and advise developers to run unfamiliar code only inside isolated virtual machines or sandboxes.
The campaign is a reminder that the interview itself has become the delivery mechanism. For teams hiring developers — or developers taking assessments — the advisory's implicit rule is the operational one: no legitimate hiring process requires executing untrusted code outside a sandbox.
TrustGrade tracks the security posture of platforms and firms in digital assets. Verified trust data: trustgrade.ai.