Friday’s joint advisory from Japan’s NPA / NCO, the FBI, DoD DC3, Australia’s ASD ACSC, and Germany’s BND / BfV puts a fresh scale on a campaign defenders already track as Contagious Interview.
Agencies say WaterPlum actors recruit software developers and IT freelancers via social, gig, and freelance platforms, impersonating legitimate AI, cryptocurrency, or NFT employers (and sometimes recruiters). During virtual interviews or coding assignments, victims are told to download and run files from developer platforms or repos — including malicious NPM packages that drop BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle (and variants). Once on the box, RATs and infostealers persist and pull browser auth, clipboard/keylogs, screenshots, wallet seeds/keys, and ID images.
From about December 2025 through July 2026, WaterPlum infected at least 30,000 devices in more than 100 countries and took funds or credentials from over 7,000 cryptocurrency wallets. Agencies put transfers to DPRK at 1.7 billion JPY (about $10.71 million USD). Primary targets named: web designers, engineers, and crypto/blockchain/Web3 specialists — especially in Japan, the US, and Europe.
The enterprise angle is not only wallet theft. Successful infections keep access in case the victim gets hired, creating a path into corporate systems. Stolen ID images feed the parallel North Korean IT-worker scheme (laptop farms, VPS obfuscation, salary funneling). NPA/FBI assess WaterPlum actors and some NK IT workers under the 313 General Bureau of the Munitions Industry Department. Japan reports its first dismantled domestic laptop farm; several hundred million JPY in crypto moved abroad. Documented IT-worker extras include source-code extortion and website defacement/downtime after hire.
POV: treat fake-recruiter interview malware and insider-shaped IT-worker hiring as one DPRK revenue stack. Sandbox untrusted assignment code; open unknown VS Code projects in Restricted Mode; EDR on developer endpoints; verify interview identity hard. Underwrite the agency counts; any higher wallet or corporate-breach tally remains Undisclosed until primaries print it.
