Image: ACSC
At a Glance Summary
| Attribute | Details |
|---|---|
| Actor or Group | North Korean WaterPlum cyber actor group (Contagious Interview) |
| Activity Type | Fake job recruitment, malware distribution, and cryptocurrency theft |
| Targets or Victims | Individual IT professionals, software developers, and web freelancers |
| Scale | Over 30,000 devices infected; $10.71 million USD claimed stolen |
| Jurisdiction / Status | Suspected state-sponsored actors under the 313 General Bureau |
| Source | Joint advisory by ASD’s ACSC, FBI, NPA, and European partners |
Executive Summary
Six international intelligence agencies recently published a joint advisory detailing massive cryptocurrency theft. The North Korean WaterPlum cyber actor group infected thousands of devices by impersonating corporate recruiters. Consequently, they tricked job seekers into downloading destructive malware during technical interviews.
What Happened During the Fake Interviews
Cybercriminals are actively using fake job interviews to breach corporate networks. A joint intelligence advisory revealed that threat actors routinely contact job seekers through freelance platforms. Next, they impersonate hiring managers representing artificial intelligence, cryptocurrency, and non-fungible token sectors.
During online interviews, the attackers employ artificial intelligence face-swapping software. Therefore, they hide their true identities from the applicants. After a few minutes, they disable their cameras and blame the outage on network issues. Then, the interviewers ask candidates to download files from code repositories. They claim this download will fix a video conferencing glitch or serve as a technical test.
Unfortunately, these downloads contain malicious packages like BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. Once executed, the software immediately deploys remote-access trojans. As a result, the attackers maintain a hidden backdoor into the victim’s network. According to the advisory, “WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities.”
Who Is Behind It
Intelligence agencies attribute these attacks to North Korea with high confidence. Specifically, the Japanese National Police Agency and the US FBI assess the group’s origins. They conclude that the North Korean WaterPlum cyber actor group reports directly to the 313 General Bureau. This bureau operates under the Central Committee of the Workers’ Party of Korea.
Additionally, authorities discovered that these hackers share physical resources with North Korean IT workers. Both groups utilized the exact same internet addresses to access domestic laptop farms. For the first time, Japanese police successfully dismantled a local laptop farm. Meanwhile, a domestic enabler provided physical computers and internet access to mask the overseas origin of the workers.
Impact and Financial Scale
The financial and operational damage remains immense. Between December 2025 and July 2026, the attackers compromised at least 30,000 devices across more than 100 countries. Furthermore, they breached over 7,000 cryptocurrency wallets. Intelligence agencies claim the threat actors funneled roughly 1.7 billion Japanese yen (about $10.71 million USD) back to North Korea.
A compromised developer machine gives attackers an easy pathway into secured corporate environments. First, the malware steals browser passwords, keystrokes, and clipboard data. Next, it captures identification documents like passports and driver’s licenses. The report notes, “Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency.” In isolated incidents, attackers even extorted clients and defaced websites following payment disputes.
What Comes Next and Defense Guidance
Individuals and businesses must implement strict verification measures to stop these attacks. Job seekers should never execute untrusted third-party code on a personal machine. If an interviewer demands you run a script to fix a video call, you must terminate the session immediately.
Companies hiring remote contractors must verify applicant identities thoroughly. First, check if the applicant’s internet protocol address matches their claimed physical location. During interviews, ask detailed questions about their listed skills and local weather conditions.
If you suspect a device is compromised, disconnect it from the internet right away. Back up your essential data safely. Then, perform a full reset of the operating system. Ultimately, following these basic guidelines helps keep your network safe from fake recruitment schemes.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!