A joint advisory from Australia’s ASD’s Australian Cyber Security Centre, the FBI, Japan’s National Police Agency and European partners details a North Korean campaign attributed with high confidence to the WaterPlum group, also known as Contagious Interview. The actors pose as recruiters on freelance platforms, often claiming to represent artificial intelligence, cryptocurrency or non-fungible token companies.
During video interviews, they may use face-swapping software before disabling their cameras and asking candidates to download code from repositories, allegedly to fix a conferencing problem or complete a technical test.
The downloads can contain malware including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. The article says these tools provide remote access and can steal browser passwords, keystrokes, clipboard contents and identity documents, while enabling cryptocurrency theft and possible access to corporate networks through compromised developer machines.
Between December 2025 and July 2026, the advisory reportedly linked the campaign to at least 30,000 infected devices in more than 100 countries and over 7,000 compromised cryptocurrency wallets. Authorities claim approximately 1.7 billion Japanese yen—about $10.71 million—was funnelled to North Korea.
The FBI and Japan’s NPA assess that WaterPlum reports to North Korea’s 313 General Bureau. Investigators also found shared internet addresses and physical resources connecting the activity with North Korean IT workers, while Japanese police dismantled a local laptop farm. The advisory recommends that job seekers avoid running untrusted code, and that organisations verify applicants’ identities and locations. Suspected victims should disconnect affected devices from the internet and reset the operating system.