Published: 2026-09-23
Categories: Threat Intelligence
Key Takeaways
A joint advisory published September 18, 2026 by law enforcement and intelligence agencies in Japan, the United States, Australia, and Germany confirmed that the North Korean threat group tracked as WaterPlum — also referred to by its campaign name, Contagious Interview — has infected more than 30,000 devices across over 100 countries between December 2025 and July 2026 [1][2]. The operation lures software developers, web engineers, and blockchain specialists with fake job offers and technical interviews, then uses the interview process itself as the delivery mechanism for malware. The group has compromised more than 7,000 cryptocurrency wallets and moved roughly 1.7 billion Japanese yen, or approximately $10.71 million, back to North Korea [1][4]. WaterPlum’s infrastructure overlaps directly with North Korea’s broader fraudulent IT worker scheme, including laptop farms that Japanese authorities dismantled for the first time this year [3]. This campaign is consistent with a broader trend in which individual developer workstations, not just enterprise perimeters, are becoming a significant target for state-directed, financially motivated intrusion.
Background
Contagious Interview is not a new phenomenon; security researchers have tracked North Korean-linked recruitment lures targeting software developers since at least 2022, with the activity cluster accumulating a long list of vendor-assigned aliases over the years, including DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, and Void Dokkaebi [1][4]. What changed on September 18, 2026 is that the campaign appears to have received its first coordinated, multi-government attribution and impact assessment. Agencies including Japan’s National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, Australia’s Australian Cyber Security Centre, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution jointly identified the operators behind this activity as WaterPlum and assessed that both WaterPlum operators and North Korea’s fraudulent remote IT worker network report to the same organization: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee [3][5].
The advisory’s scope covers the period from approximately December 2025 through July 2026, during which WaterPlum operators posed as recruiters and hiring managers from ostensibly legitimate artificial intelligence, cryptocurrency, and NFT companies on professional networking sites, job boards, and freelance marketplaces [2][4]. Targets who engaged with these fake opportunities were routed into staged technical interviews or coding assessments that required them to download and execute a project, or to “fix a bug,” on a video call [4]. In effect, this pretext is engineered to get a developer to run attacker-supplied code on their own machine. This technique is what distinguishes Contagious Interview from conventional phishing: rather than attacking a corporate network boundary, it recruits the victim into personally executing the initial payload under the guise of professional obligation, a dynamic that may prove durable because it exploits normal hiring behavior rather than a technical vulnerability.
The advisory also connects WaterPlum to Japan’s first confirmed dismantlement of a North Korean laptop farm, a facility where accomplices hosted company-issued devices that North Korean IT workers accessed remotely to draw salaries under false identities. Investigators found that WaterPlum operators and North Korean IT workers reused the same IP addresses, including when accessing laptop farms and when applying for legitimate remote jobs, providing direct infrastructure evidence that the fake-interview crypto-theft campaign and the fraudulent employment scheme are run by overlapping personnel rather than parallel, unrelated operations [3].
Security Analysis
WaterPlum’s technical arsenal has diversified considerably since the campaign’s earlier years, when BeaverTail and InvisibleFerret were its primary tools. The September 2026 advisory names five malware families currently in active use, each serving a distinct role in the infection chain, summarized in the table below [1][2][4].
| Malware | Type | Primary Function |
|---|---|---|
| BeaverTail | JavaScript malware, often bundled in npm packages | Initial loader and browser credential stealer |
| InvisibleFerret | Python-based backdoor | Persistent remote access and secondary payload delivery |
| OtterCookie | JavaScript RAT / infostealer | Keystroke, clipboard, and credential capture |
| OtterCandy | Combined RAT and infostealer | Merges OtterCookie capabilities with expanded remote-control functions |
| StoatWaffle | Modular Node.js malware | Delivered via malicious Visual Studio Code projects; extensible payload framework |
Collectively, these tools give WaterPlum operators the ability to harvest browser-stored credentials, clipboard contents, keystrokes, documents, and screenshots, along with the specific target of cryptocurrency private keys and seed phrases — the asset class that converts a compromised developer workstation directly into stolen funds [2][4]. The consistent presence of a JavaScript-based initial loader distributed through npm-style packages or IDE projects reflects a broader pattern this year in which North Korean-linked actors have repeatedly used the developer tooling ecosystem itself — package registries, IDE extensions, and build scripts — as an attack surface, a pattern also visible in the unrelated but contemporaneous Sapphire Sleet compromise of the Mastra AI npm ecosystem in June 2026 [6].
WaterPlum’s operational infrastructure extends well beyond malware. The group relies on commercial VPN services, including Astrill VPN and Mullvad, to mask the true origin of its command-and-control traffic and to route stolen funds and remote-access sessions through jurisdictions that complicate takedown efforts [1][4]. It also recruits proxies through Discord communities — one identified server carried the name “Mouse Review” — offering payments in the range of $3,000 to $5,000 to Western and Latin American individuals willing to pose as job candidates or to lend their identities to bypass sanctions screening and compliance checks during the hiring process [1][4]. This recruitment layer means that some of the human interactions victims or hiring companies encounter during the fake interview process may not originate from North Korea directly, but from paid intermediaries who provide a more convincing regional accent, time zone, or cultural fluency, complicating detection efforts that rely on identifying North Korean behavioral or linguistic tells.
The financial scale of the operation — over 7,000 compromised cryptocurrency wallets and $10.71 million transferred to North Korea in an eight-month window — is significant in absolute terms, though CSA has not conducted a comparative ranking against other state-directed cybercrime operations disclosed in 2026. The joint advisory’s emphasis on overlapping infrastructure with North Korea’s IT worker fraud network suggests the true financial impact of this organizational structure, encompassing both salary fraud and direct theft, is considerably larger than the crypto-theft figure alone [1][3].
Recommendations
Immediate Actions
Organizations that use external recruiters, freelance platforms, or contractor pipelines to source technical talent should treat any hiring process that requires a candidate to execute code outside of a sandboxed or company-managed environment as a red flag, and should suspend live coding assessments that involve running arbitrary downloaded projects until the assessment platform can be verified. Security teams should also distribute the known malware family names and behavioral indicators — BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle — to hiring managers and technical interviewers, since these teams, not security staff, are the first people likely to encounter a malicious “coding test” package. Any developer who has completed a take-home assessment or live coding exercise for an unfamiliar or unverified employer within the December 2025 through September 2026 window should be advised to rotate credentials, review browser-stored passwords, and audit any cryptocurrency wallets accessed from that device.
Short-Term Mitigations
Engineering organizations should isolate technical interview and assessment environments from production credentials and personal cryptocurrency holdings by requiring that all coding exercises run inside disposable virtual machines or cloud-hosted sandboxes rather than on a candidate’s or employee’s primary workstation. Endpoint detection tooling should be tuned to flag the specific execution patterns associated with this campaign, including Node.js processes launched from freshly downloaded, unsigned project directories and Python processes establishing outbound connections shortly after a video-call screen-sharing session. Given WaterPlum’s demonstrated use of commercial VPN exit nodes for command-and-control traffic, organizations conducting technical hiring at scale should also consider additional identity verification for remote interview platforms, while recognizing that the group’s use of paid regional proxies limits the reliability of geography alone as a detection signal.
Strategic Considerations
The overlap between WaterPlum’s crypto-theft operations and North Korea’s fraudulent IT worker network means that organizations should treat technical hiring security and remote contractor identity verification as a single risk domain rather than two separate programs. Enterprises with active remote-hire pipelines should incorporate identity-verification steps that go beyond document checks, since the campaign’s proxy-recruitment model already anticipates and defeats superficial screening. Finally, because this activity cluster has demonstrated a multi-year ability to rebrand, add malware families, and shift infrastructure while retaining the same underlying operators and organizational sponsor, defenders should assume that today’s indicators of compromise will have a short shelf life and should prioritize durable behavioral and process controls — sandboxed assessments, credential isolation, and contractor identity verification — over indicator-based detection alone.
CSA Resource Alignment
WaterPlum’s use of npm-distributed JavaScript loaders and IDE-based malicious projects connects directly to CSA’s prior research on North Korea-linked developer supply chain attacks, most specifically “Sapphire Sleet Poisons Mastra AI npm Supply Chain,” which documented a separate June 2026 campaign in which the North Korean actor Sapphire Sleet compromised 145 packages in the Mastra AI framework ecosystem [6]. That research note’s analysis of npm-based initial access, maintainer account compromise, and JavaScript payload staging maps closely onto the BeaverTail and StoatWaffle delivery mechanisms described in this note, and organizations that implemented the earlier note’s package-provenance and dependency-review recommendations may be better positioned to detect a similar delivery vector, though this has not been independently verified against WaterPlum’s specific tooling.
More broadly, this campaign reinforces the thesis of CSA’s “GlassWorm Returns: Developer Toolchain Worm Expands to GitHub and npm” and the related whitepaper “The Developer Toolchain as Enterprise Attack Surface: Systemic Risk from IDE, Registry, and CI/CD Compromise,” which together found that the individual developer’s toolchain — IDE, package manager, and local credential store — has become a recurring attack surface for supply-chain-oriented threat actors, state-sponsored and criminal alike [7][8]. The mitigations those publications recommend, including sandboxing of untrusted developer tooling and credential isolation for build and assessment environments, apply directly to the technical-interview attack vector described here.
Finally, the governance dimension of this campaign — specifically, the risk that a hiring or contractor-onboarding process becomes an initial-access vector — falls within domains of CSA’s AI Controls Matrix (AICM) v1.1 addressing human resources security and identity and access management, which organizations can use to formalize controls around contractor and interview-candidate access to code, credentials, and execution environments during technical hiring [9].
References
[1] The Hacker News. “Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto.” The Hacker News, September 2026.
[2] BleepingComputer. “North Korean WaterPlum hackers infected 30,000 devices worldwide.” BleepingComputer, September 2026.
[3] SecurityWeek. “Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme.” SecurityWeek, September 2026.
[4] Security Affairs. “Contagious Interview: 30,000 devices infected by a fake job interview.” Security Affairs, September 2026.
[5] Infosecurity Magazine. “North Korean Attackers Hit 30,000 Devices and Steal $10.7m.” Infosecurity Magazine, September 2026.
[6] Cloud Security Alliance. “Sapphire Sleet Poisons Mastra AI npm Supply Chain.” CSA Labs, June 2026.
[7] Cloud Security Alliance. “GlassWorm Returns: Developer Toolchain Worm Expands to GitHub and npm.” CSA Labs, March 2026.
[8] Cloud Security Alliance. “The Developer Toolchain as Enterprise Attack Surface: Systemic Risk from IDE, Registry, and CI/CD Compromise.” CSA Labs, May 2026.
[9] Cloud Security Alliance. “AI Controls Matrix (AICM) v1.1.” Cloud Security Alliance, 2026.