Japan, FBI and partners expose North Korean fake recruiting operation targeting crypto developers

Japan, FBI and partners expose North Korean fake recruiting operation targeting crypto developers

N
News Editor
2026-09-20 06:15:22
Japan’s National Police Agency, the U.S. Federal Bureau of Investigation and other international agencies said on Sept. 18 that a North Korean hacking group known as WaterPlum, also called “Contagious Interview,” has been posing as recruiters and crypto companies to trick developers into running malware. According to the joint disclosure, the group infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026, moving funds or stealing account credentials from more than 7,000 crypto wallets, with at least $10.71 million in crypto assets involved. Authorities said the campaign differs from earlier attacks focused on exchanges and large institutions because it pushes deeper into the individual layer of the industry, targeting developers, freelancers and other Web3 workers. The malware is often delivered through coding tests, project repositories and fake troubleshooting tasks tied to video interviews. The agencies named several malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, and warned that some projects abuse VS Code task settings to execute code automatically. The notice also linked the operation to North Korean IT workers who allegedly use stolen identity documents to seek overseas jobs, including at crypto firms. Japanese authorities said they had identified, for the first time, a Japan-based remote work hub used to help such workers disguise their location and identity.

Japan’s National Police Agency, the U.S. Federal Bureau of Investigation and other international agencies said on Sept. 18 that the North Korean hacking group WaterPlum, also known as “Contagious Interview,” has spent years posing as recruiters or crypto companies and luring developers into running malicious code through coding tests and project collaboration requests.

The joint notice said that from December 2025 to July 2026, the group infected at least 30,000 devices in more than 100 countries. It moved funds or stole account credentials from more than 7,000 crypto wallets, involving at least $10.71 million in crypto assets.

Targets shifted from institutions to individual developers

Authorities said the campaign differs from earlier attacks that mainly focused on trading platforms and large organizations. WaterPlum has pushed further down the stack, targeting individual developers, freelancers and Web3 workers. The agencies said the attackers do more than steal wallet funds directly. They also use compromised computers and stolen identity data to reach the victim’s employer, creating openings for trade secret theft, extortion and even follow-on job fraud carried out in the victim’s name.

The attack often starts with what looks like a normal job offer

According to the notice, WaterPlum’s most common entry point is not a phishing email but a seemingly ordinary job opportunity. The attackers impersonate AI, cryptocurrency or NFT companies and contact software developers through social media, online hiring platforms, gig platforms and freelancer marketplaces. After initial contact, they usually set up a video interview or ask the applicant to complete a programming test.

The actual compromise happens during the so-called technical assessment. The attacker may send a code repository and ask the target to run the project locally, fix bugs or troubleshoot why video meeting software is not working. On the surface, these look like ordinary JavaScript, Python or Visual Studio Code projects. Inside, they contain malicious code.

The agencies said WaterPlum frequently relies on trojanized NPM packages and has used multiple malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Some malicious projects abuse the .vscode/tasks.json configuration file so code runs automatically once a user opens and trusts the VS Code folder. From the victim’s perspective, the process may look simple: download the code, open the project and run the program as instructed by the “interviewer.” By then, the malware may already be installed in the background.

What gets stolen goes far beyond wallet balances

After gaining initial access, the attackers deploy remote access trojans to keep long-term control of the device and use infostealers to collect data. The notice listed the main targets as:

  • Accounts and passwords saved in browsers;
  • Clipboard contents, keystrokes and screenshots;
  • Crypto wallet private keys, seed phrases and related data;
  • Files stored on the computer and in shared folders;
  • Images of identity documents such as driver’s licenses and passports.

The stolen information is then sent to servers controlled by the attackers. The agencies warned that even if a victim’s wallet holds no assets at the time, leaked private keys or seed phrases still let the attackers watch the address over time and move funds later once assets arrive.

The risk does not stop at personal wallets. Developers often have access to company code repositories, cloud services and internal systems. WaterPlum may use saved credentials and existing permissions on the compromised device to enter employer, client or partner systems, steal trade secrets, move laterally inside corporate networks and use sensitive data for extortion.

Stolen identity documents are also used for overseas job fraud

The notice said driver’s licenses, passports and other identity documents stolen by WaterPlum serve another purpose: they can be handed to North Korean IT workers who then impersonate the victims while applying for jobs abroad and earning foreign currency. WaterPlum mainly spreads malware through fake recruiting, while North Korean IT workers pose as overseas developers to get hired by companies. Authorities said the two operations overlap in both personnel and infrastructure.

Japan’s National Police Agency and the FBI said they assess that WaterPlum members and some North Korean IT workers belong to Bureau 313 of the Munitions Industry Department under the Central Committee of the Workers’ Party of Korea.

Residential properties abroad were used as remote work hubs

To get around employer checks on identity and work location, North Korean IT workers cooperate with intermediaries outside the country. Those intermediaries place work computers in local residences, provide identity information and receive salary payments on the workers’ behalf, while the actual work is carried out remotely by people located in North Korea, Russia and elsewhere. The notice described these setups as remote work hubs that disguise the real operator’s location and identity.

Using this model, North Korean IT workers can log into company systems through computers and internet connections located in Japan or the United States, making employers believe the worker is physically there. The local facilitators also receive company-issued laptops, provide identity documents and bank accounts, and then forward the wages to the actual operator.

Japanese authorities said they had, for the first time, uncovered one such hub inside Japan. The investigation found that the people involved not only helped North Korean IT workers disguise their identities and take on jobs, but also transferred funds worth hundreds of millions of yen, including crypto assets, to destinations outside Japan. The notice warned that companies or individuals who provide work, pay compensation, or help supply identity information, bank accounts or remote devices to North Korean IT workers may violate local law and sanctions related to North Korea.

The agencies also said the risks created after these workers enter a company are not limited to wages flowing to North Korea. In one case, a North Korean IT worker extorted an employer over a pay dispute and published the company’s proprietary source code. In another, a worker hired to maintain a website maliciously altered the site and made it inaccessible.

Suspected North Korean applicant targeted a Japanese crypto exchange

Crypto companies are one of the sectors North Korean IT workers particularly seek to enter.

In May 2025, a Japanese cryptocurrency exchange received an application for an engineering role from a person suspected of being a North Korean IT worker. According to the notice, the applicant accessed the hiring page through a VPN and submitted a falsified résumé. The résumé appeared unusually broad: the applicant claimed knowledge of a large number of programming languages, blockchain technologies, cryptocurrency technologies and cloud services, listing more than 10 items of knowledge and experience in each category. The personal history also included a European university background and work experience across multiple cities in Europe and Asia within a short period.

During a video interview, the applicant said he was born in Malaysia, lived in Finland and spoke Malay and Chinese as native languages. But his English ability did not match the education and work background he claimed. The notice said he could answer only simple questions and could not explain most of the technical skills listed on the résumé in detail.

The agencies also summarized other common signs seen in interviews with suspected North Korean IT workers: refusing to meet in person, asking to be paid in cryptocurrency, frequently looking at another screen, occasional background voices from other people, and repeated video or audio lag. Looking repeatedly at another screen may indicate the applicant is reading answers supplied by someone else, the notice said. Even if only one candidate appears on camera, multiple people may be working together behind the scenes to assemble the technical profile shown on the résumé.

Deleting malware is not enough once a device has been exposed

The agencies said that once someone has run code from an unknown source on a computer, they should not assume the device or wallet is safe simply because no wallet funds have been moved yet. Malware may already have captured private keys, seed phrases or browser credentials without using them immediately. Attackers may also keep a backdoor on the device and wait for a better moment to move funds.

The notice advised users not to run code provided by strangers on devices that store crypto assets or handle sensitive data. If testing is unavoidable, it should be done in a sandbox or virtual machine isolated from the normal environment, and the project should be checked in advance for obfuscated code, unreadable code or code that automatically downloads other files.

The agencies also warned users to be especially cautious with scripts containing commands such as curl, base64, mshta and Invoke-WebRequest, which can be used for downloading, encoding or concealed execution. If the purpose is unclear, do not run them. If antivirus software has flagged an infection, or if a suspicious recruiter’s program has already been run, the device should be disconnected from the network immediately.

Even if the malware is later removed, the notice said users should assume wallet data has been exposed, create a brand-new wallet on a separate secure device, move all assets and store the new seed phrase offline. Because an infected computer may still contain an undiscovered backdoor, the safest response is to back up necessary files and then fully reinstall or reset the operating system rather than continue using the original environment.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.