Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

North Korea's WaterPlum hit 30,000 devices through fake job interviews, advisory says

Seven agencies in Japan, the U.S., Australia and Germany say the group posed as AI and crypto employers, planted malware via coding tests and moved $10.71 million to Pyongyang.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1WaterPlum infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, agencies said.
  • 2Agencies said the group took funds or account credentials from over 7,000 crypto wallets and sent 1.7 billion yen, about $10.71 million, to North Korea.
  • 3The advisory links WaterPlum to North Korean IT workers and urges tighter hiring checks and sandboxed code review.

The news

A joint advisory published September 18, 2026 by agencies in Japan, the United States, Australia and Germany says North Korea's WaterPlum hacking group infected at least 30,000 devices in more than 100 countries by posing as employers and running fake job interviews.

The group is commonly referred to as Contagious Interview. The advisory was issued by Japan's National Police Agency and National Cybersecurity Office, the FBI, the Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND and BfV. It says that from around December 2025 through July 2026 the group stole funds or credentials from more than 7,000 cryptocurrency wallets and moved 1.7 billion yen, about $10.71 million, to North Korea.

According to the agencies, WaterPlum actors impersonate artificial intelligence, cryptocurrency and NFT companies, and have used recruiting services, to approach developers and IT professionals. During technical interviews or coding assignments, targets are told to download and run files, sometimes framed as fixing a video-call error. The files include malicious npm packages, which are JavaScript code libraries, carrying malware families such as BeaverTail, InvisibleFerret and OtterCookie. Another family, StoatWaffle, hides in Visual Studio Code projects that run code automatically when a developer opens and trusts the folder.

The advisory warns that a compromised developer can become a gateway into their employer, opening the door to spying, stolen intellectual property and wider movement across corporate systems. It says the NPA and FBI assess that WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, and that both groups used the same IP addresses. The agencies said the actors used AI face-swapping software during video interviews, then switched off video citing network problems.

Japanese authorities said they identified and dismantled a laptop farm for the first time in Japan. In such a setup, a local accomplice keeps employer-issued computers running, often at home, so North Korean IT workers can operate them remotely while hiding where they actually work. The advisory also describes one IT worker who extorted a company and published its source code, and another hired for website maintenance who defaced the client's site. BleepingComputer reported on the advisory on September 19, 2026.

The numbers

Devices infected
30,000+
Countries affected
100+
Crypto wallets compromised
7,000+
Crypto sent to North Korea
¥1.7 billion (~$10.71 million)

Why CEOs should care

For CISOs, WaterPlum turns an employee's personal job search into a corporate breach. A developer who runs a take-home test on a work laptop can hand over browser passwords, keys and source code access. The advisory's own recommendations are concrete: deploy endpoint detection and response tools, open unfamiliar Visual Studio Code projects only in Restricted Mode, inspect .vscode/tasks.json files before trusting a folder, and treat any machine that ran suspect code as compromised. It also flags scripts containing strings such as curl, base64 or mshta as warning signs before anything is run.

For HR leaders and hiring managers, the same actors are applying for your jobs. The agencies suggest checking whether an applicant's IP address matches their claimed location, calling listed phone numbers, probing every skill on an unusually broad résumé and watching for refusals to meet in person or requests for crypto payment. Build these checks into contractor and freelance onboarding, not just full-time hiring.

For CFOs and general counsel, the advisory notes that paying North Korean IT workers may breach domestic law and sanctions. Ask procurement whether subcontractors could be passing work to unknown parties, and add contract clauses that require identity verification down the chain.

The bigger picture

The advisory is notable for its breadth: seven agencies across four countries, and an explicit link between hacking for crypto and IT-worker schemes that generate salaries for the state. It frames developers as both the target and the entry point. For companies, the $10.71 million stolen arguably understates the risk, because the advisory also warns that infected developer machines can give the group a way into their employers' networks and code.

What’s next

Expect more enforcement against domestic facilitators, since the FBI says it continues to identify and prosecute U.S.-based enablers of North Korean IT workers. Security teams should add the advisory's malware families and techniques to their detection and hiring playbooks.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

North KoreaFBIWaterPlumInsider risk

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.