A coordinated cyber-espionage campaign linked to North Korea compromised more than 30,000 devices across over 100 countries and drained at least $10.71 million from more than 7,000 cryptocurrency wallets, according to a joint advisory issued Thursday by law enforcement agencies in the United States, Japan, Australia, and Germany.

    The operation, tracked internationally as WaterPlum and also known as Contagious Interview, used fake job interviews and bogus coding tests to lure web designers, engineers, and blockchain specialists into downloading malware. The stolen funds ultimately flowed to Pyongyang, authorities said.

    Japan’s National Police Agency led the analysis behind the advisory. The FBI and cybersecurity agencies from the other participating countries contributed intelligence gathered over months of investigation.

    The campaign ran from late 2025 through July 2026, according to investigators. Attackers posed as recruiters from legitimate-sounding AI, cryptocurrency, and NFT companies, approaching targets through social media, job boards, freelance platforms, and gig-work sites.

    During the fake interview process, victims were asked to complete technical assignments or coding tests that required downloading files hosted on popular development and code-sharing platforms. Those files contained malware that embedded itself in the victim’s operating environment, giving attackers persistent remote access.

    Malware Arsenal and Data Theft

    The malware families deployed in the campaign include BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle. These tools enabled keylogging, screenshot capture, clipboard monitoring, password extraction, and unauthorized remote access, investigators found.

    Attackers specifically targeted cryptocurrency wallet credentials, including private keys and seed phrases. The stolen assets were transferred to wallets controlled by WaterPlum, with the Japanese police estimating the haul at roughly ¥1.7 billion (approximately $10.8 million).

    MetricValue Devices infected 30,000+ Crypto wallets compromised 7,000+ Countries affected 100+ Cryptocurrency stolen $10.71 million

    Note: Figures are drawn from the joint advisory issued by law enforcement and cybersecurity agencies.

    Beyond direct theft, the advisory warned that compromised machines could later serve as entry points into corporate networks once jobseekers secured legitimate employment. Stolen identity documents could also be repurposed to impersonate victims in further fraud.

    “Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims’ employers, clients, or contracting parties,” the advisory said. “The actors can also use stolen sensitive information for extortion.”

    The Other Side of the Scheme

    The recruiter campaign is the mirror image of North Korea’s better-known tactic: placing its own IT workers inside Western and allied companies under false identities. That parallel operation has been extensively documented and generates significant foreign currency for the regime.

    Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Many are supported by accomplices who operate “laptop farms” — residences equipped with computers that allow remote workers to appear as though they are based in the country where they were hired.

    The IT worker fraud is thought to net Kim Jong Un’s regime upwards of $500 million a year, according to estimates cited in the advisory. Workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state.

    Law enforcement suspects that WaterPlum and these broader IT operations are linked to Bureau 313, a division under North Korea’s Workers’ Party Central Committee frequently cited in connection with state-sponsored cyber activities. The Japanese police have also tied the group to the 313th General Bureau under the Ministry of Munitions Industry, which is responsible for nuclear weapons development and foreign currency acquisition.

    The bitFlyer Connection

    One suspicious application at Japanese crypto exchange bitFlyer illustrates how the employment scam attempts to penetrate legitimate companies. In May 2025, an applicant submitted a resume through the exchange’s online portal claiming to have graduated from a European university and worked around the world.

    During the interview process, the applicant’s English proficiency was poor enough to raise serious doubts, and the person was not hired. Investigators later found that IP addresses associated with the WaterPlum group overlapped with the bitFlyer application, suggesting a direct technical link between the malware operation and the employment fraud.

    The applicant had used stolen identity data and VPN services, refused to relocate to Japan, and insisted on payment in cryptocurrency. Interviewers noted unexplained interruptions and multiple voices in the background.

    Those red flags match a broader pattern authorities have documented among fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds and extensive work experience, but their language skills may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, and requests for crypto payment.

    Some fraudulent workers use AI face-swapping software during video calls, which can produce visual artifacts and prompt them to disable their cameras shortly after a meeting begins. In the recruiter campaign, WaterPlum operators reportedly appeared on camera only for the first few minutes before blaming network problems and suggesting the victim also turn off their video.

    Japanese Chief Cabinet Secretary Yoshimasa Hayashi addressed the threat on September 18, saying it “poses a threat not only to Japan but to information security and economic activity worldwide.” He urged IT professionals and private companies to adopt appropriate security precautions.

    Recommendations

    Authorities recommended that software developers avoid running unfamiliar code directly on primary work systems. Instead, they suggested using virtual machines or isolated computing environments when handling new or untrusted code to limit the impact of potential breaches.

    For organizations that suspect they may have engaged a fraudulent North Korean IT worker, the advisory recommended launching a full forensic investigation and assuming that credentials and other sensitive data have already been compromised.

    The scale of the operation means some applicants inevitably succeed, even as employers become more familiar with the warning signs. The dual-pronged approach — placing fraudulent workers inside companies while simultaneously attacking jobseekers — reflects what investigators describe as a strategic effort to acquire digital assets and credentials from highly specialized, high-value targets.

    Local collaborators in countries including China, Russia, and parts of Africa provided identity verification images to North Korean personnel stationed abroad, according to the Japanese police. These materials were used to secure corporate work or freelance contracts on crowdsourcing platforms. To create the impression that work was being performed domestically, collaborators also supplied local computers remotely controlled by North Korean personnel.

    Payments for these services were deposited into accounts held by the collaborators, from which funds could be laundered and transferred to North Korea. The total amount believed to have been sent overseas reaches hundreds of millions of yen, investigators said.

    Share.

    Comments are closed.