Seven law enforcement and intelligence agencies from Japan, the United States, Australia and Germany issued a joint alert on Sept. 18, saying the North Korea-linked hacking group WaterPlum posed as recruiters from AI, cryptocurrency and NFT companies and used fake job interviews to get software engineers to run malicious code. The notice said that from December 2025 to July 2026, the group compromised at least 30,000 computers in more than 100 countries and stole funds or account credentials from more than 7,000 cryptocurrency wallets.
The alert said the stolen crypto assets were ultimately transferred to wallets tied to North Korea. The total reached at least JPY 1.7 billion, or about $10.71 million. It added that the main victims were individuals, including web designers, engineers, and professionals working in cryptocurrency, blockchain and Web3, with their personal wallets being targeted.
Joint alert identifies WaterPlum
The notice used the name WaterPlum for the group. In the security industry, the campaign is commonly known as "Contagious Interview." Japan's National Police Agency and the Federal Bureau of Investigation assessed that WaterPlum members, along with some North Korean IT workers, belong to Bureau 313 under the Munitions Industry Department of the Central Committee of the Workers' Party of Korea.
The Japanese signatories were the National Police Agency and the National Center of Incident Readiness and Strategy for Cybersecurity. The U.S. side included the FBI and the Department of Defense Cyber Crime Center, or DC3. Australia was represented by the Australian Cyber Security Centre under the Australian Signals Directorate. Germany's signatories were the Federal Intelligence Service, or BND, and the Federal Office for the Protection of the Constitution, or BfV.
Malware hidden in coding tests
According to the alert, WaterPlum searched for targets on social platforms, job sites and freelance marketplaces, then asked applicants to join online technical interviews or complete coding assignments. During the process, the operators told victims to download and run files hosted on code repositories, saying the files were needed either to finish the assignment or to fix a video meeting software issue.
Most of those files were NPM packages embedded with malware. NPM is the package manager used by Node.js developers to install third-party libraries. The alert listed BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle among the malware families used in the campaign.
StoatWaffle was described as disguising itself as a blockchain-themed project. If a victim opened the folder in Visual Studio Code and chose to trust the author, configuration files inside the project could automatically execute code.
After gaining access, WaterPlum used remote access trojans, or RATs, to maintain control, then deployed infostealers to send data back to its own servers. The stolen information included browser-stored usernames and passwords, clipboard contents, keystrokes, screenshots, wallet private keys and seed phrases. Driver's license and passport photos were also taken. The alert warned that stolen identity documents could be used by North Korean IT workers to impersonate others on freelance platforms, while stolen credentials could be used to break into companies where victims worked or collaborated.
Behavior observed by investigators
The alert also described operational habits observed by investigators. WaterPlum members used AI face-swapping software during online interviews, then turned off their cameras after a few minutes and asked applicants to do the same, citing unstable internet connections.
Investigators said the operators used text-to-speech tools to practice Japanese pronunciation, and consistently relied on free tiers of machine translation and AI services. On North Korean holidays, members of the hacking team paused their usual operations and spent time playing games or watching football videos, according to the notice.
Japan says it dismantled a laptop farm for the first time
The alert devoted two additional sections to North Korean IT workers. It said these workers were mostly based in North Korea, China or Russia, with a smaller number in Africa and Southeast Asia, and earned foreign currency by taking jobs under false identities through so-called laptop farms set up by facilitators. Those farms were typically located in the homes of facilitators, where employer-issued computers were placed and then remotely operated by North Korean personnel.
Japanese police said they identified and dismantled a laptop farm in Japan for the first time. They also obtained evidence showing that North Korean IT workers transferred assets worth hundreds of millions of yen overseas, including cryptocurrency. The National Police Agency and the FBI said WaterPlum and North Korean IT workers used the same set of IP addresses when connecting to laptop farms, using crowdsourcing platforms and applying for jobs at Japanese cryptocurrency exchanges. The alert cited that overlap as evidence of a link between the two.
Advice for developers and victims
The alert advised developers not to run code provided by strangers on computers that store crypto assets or personal information. If code must be executed, it should be isolated in a sandbox or virtual machine. It also warned users to be cautious when commands contain strings such as curl, base64 or mshta, and said Visual Studio Code should be used in Restricted Mode when opening unfamiliar projects.
For people who may already be infected, the notice said they should assume wallet data has been exposed, create a new wallet on a different device, move all assets, and then reinstall the operating system.
Questions addressed in the notice
How WaterPlum broke into engineers' computers through fake interviews
The alert said WaterPlum posed as recruiters from AI, cryptocurrency or NFT companies and asked applicants to run coding assignment files during interviews. Many of those files were NPM packages carrying malware such as BeaverTail and OtterCookie. Once executed, the victim's computer could be remotely controlled.
What to do after running code during an online interview and getting infected
The joint notice from Japan, the U.S., Australia and Germany said victims should disconnect from the internet first and assume that wallet private keys and seed phrases have been exposed. It advised creating a new wallet on another device, moving all assets, and reinstalling the operating system. The alert said WaterPlum had already stolen funds or credentials from more than 7,000 wallets.

