North Korean hackers posing as recruiters infected at least 30,000 computers in more than 100 countries over eight months, according to a joint advisory from law enforcement and intelligence agencies in the United States, Japan, Australia and Germany. The operators lured software developers into fake job interviews and used the access to drain more than 7,000 cryptocurrency wallets.

The advisory, dated Sept. 18 and published by the FBI’s Internet Crime Complaint Center, puts the haul at 1.7 billion yen, or about $10.71 million, in cryptocurrency transferred to North Korea between December 2025 and July 2026. Its most consequential finding is organizational. The FBI and Japan’s National Police Agency (NPA) assess that the hacking group, which Japanese authorities track as “WaterPlum” and the security industry calls “Contagious Interview,” works under the same regime body as the North Korean IT workers who take remote jobs at Western companies under false identities.
That link matters for U.S. employers. It means the same operators may be both stealing from job seekers and trying to get hired by the companies those job seekers work for, and investigators say they have found shared infrastructure connecting the two efforts.
What the Advisory Found
The advisory was co-signed by seven agencies: Japan’s NPA and National Cybersecurity Office, the FBI, the Department of Defense Cyber Crime Center (DC3), the Australian Signals Directorate’s Australian Cyber Security Centre, and Germany’s Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV). Its core findings:
- WaterPlum infected at least 30,000 PCs in over 100 countries, including Japan and the United States, from roughly December 2025 through July 2026.
- The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain and Web3 technology, many of them freelancers.
- The actors took funds or credentials from more than 7,000 cryptocurrency wallets and moved at least $10.71 million to the Democratic People’s Republic of Korea (DPRK).
- The NPA and FBI assess that both WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which reports to the Central Committee of the Workers’ Party of Korea.
- A first for Japan. Japanese authorities for the first time identified, investigated and dismantled a “laptop farm” run by an enabler inside Japan, and found evidence that the group moved several hundred million yen in cryptocurrency out of the country.
The Munitions Industry Department oversees North Korea’s weapons production, including its missile programs. Revenue from both the hacking and the IT work therefore feeds the part of the regime that builds its weapons. Homeland411 has examined how hard this kind of money is to trace in its reporting on proliferation financing, which moves through shell companies and offshore intermediaries. Cryptocurrency theft adds another channel that is fast and crosses borders easily.
One Regime Unit, Two Revenue Streams
The advisory describes two operations that overlap. The first is the Contagious Interview campaign: WaterPlum operators pose as hiring managers and infect the people they claim to be recruiting. The second is the long-running IT worker scheme, in which North Koreans, usually working from North Korea, China or Russia, win freelance contracts and full-time remote jobs using borrowed or stolen identities.
The link between the two is technical. According to the advisory, WaterPlum actors and North Korean IT workers “used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange.” Some WaterPlum operators also do contract web development work for clients themselves.
The two operations also feed each other. Identity documents stolen from infected developers, such as driver’s licenses and passports, can be used by IT workers to pose as those victims and win new contracts. Credentials taken from a freelancer’s laptop can give the operators access to the freelancer’s clients and employers. In the advisory’s words, successful infections enable “espionage, intellectual property theft, and additional lateral movement in corporate environments.”
The IT workers’ activity is also not limited to earning money. The advisory cites one case in which a North Korean IT worker extorted a company over payment and published its proprietary source code, and another in which a worker hired for website maintenance defaced the client’s site and took it offline. The FBI warned in January 2025 that IT workers were stealing data and extorting employers after being discovered.
The advisory describes a five-stage chain that turns a recruiting pitch into stolen wallets, identities and access to employers’ networks. Graphic: Homeland411 / Source: Joint FBI-Japan NPA advisory
How a Job Interview Becomes a Breach

The attack begins with a recruiting pitch. WaterPlum operators contact targets through social media, job boards, gig platforms and freelance marketplaces, often posing as legitimate AI, cryptocurrency or NFT companies. At some point in the hiring process, the candidate is asked to download and run code, either to complete a technical assignment or to “fix” an error in the video-conferencing software during a live interview.
That code is the payload. The advisory names five malware families delivered through malicious packages on npm, the default package manager for the Node.js JavaScript runtime:
- BeaverTail is JavaScript malware hidden in npm packages and pulled from GitHub or Bitbucket.
- InvisibleFerret is a Python-based backdoor.
- OtterCookie is a JavaScript remote-access trojan (RAT) and information stealer.
- OtterCandy combines the features of OtterCookie and another RAT, RATatouille.
- StoatWaffle is a modular Node.js family delivered through blockchain-themed Visual Studio Code projects. A hidden configuration file runs code automatically as soon as the victim opens the folder and chooses to trust it.
Once installed, the RATs keep the operators connected while infostealers collect saved browser passwords, clipboard contents, keystrokes, screenshots, wallet private keys and seed phrases, and any identity documents on the machine.
The advisory also describes the operators’ own behavior. They conducted interviews using “AI face-swapping software,” then switched off their cameras after a few minutes and told the target to do the same, blaming network problems. They practiced Japanese pronunciation with text-to-speech tools and relied on free machine-translation and AI services. On North Korean holidays, they “played games and watched soccer videos” instead of working. U.S. intelligence agencies warned in 2023 that adversaries would use generative AI to make social engineering more convincing, and the face-swapped interviews described here are an example of that happening.
Why This Is a Homeland Security Problem
On its face, a campaign aimed at individual freelancers and crypto holders looks like fraud. There are three reasons it is a larger concern for U.S. networks.
First, a developer’s laptop holds far more than the developer’s own money. It usually stores access tokens for cloud accounts, build pipelines and source-code repositories. A separate North Korean group, Jade Sleet, showed how that access can be used. SentinelOne reported on Sept. 21 that the group compromised a DevOps engineer at an India-based IT services provider through a fake GitHub project containing weaponized Terraform files, then installed two macOS backdoors. “Endpoints used for development carry access to cloud, pipelines and source code, which makes monitoring a high priority,” the researchers wrote. Jade Sleet, also tracked as TraderTraitor, is the group the FBI blamed for the roughly $1.5 billion theft from the Bybit exchange in February 2025.
Second, the scheme depends on people inside the United States. The advisory says enablers in Japan, the United States and other countries set up and run laptop farms, which are rooms of company-issued computers that North Korean workers control remotely so they appear to be working domestically. The FBI said it “continues to identify and prosecute US-based actors providing illicit facilitation services” across many jurisdictions. In May, two U.S. nationals were each sentenced to 18 months in federal prison for running laptop farms that helped North Korean IT workers get jobs at nearly 70 American companies and generated more than $1.2 million for Pyongyang. “These were not paperwork violations,” prosecutors said at the time. “They were deliberate acts that exposed U.S. businesses, compromised trust, and supported one of the world’s most dangerous adversaries.”
Recruiting for these roles is now happening openly. The threat intelligence firm Silent Push reported last week that North Korean IT workers are using Discord servers to recruit Western and Latin American citizens as paid “proxies” who sit for interviews on their behalf, offering $3,000 to $5,000 and a 35/65 split of the resulting salary. Those recruits face legal risk. The advisory warns that knowingly giving payment or ID images to North Korean actors “could constitute a crime,” and paying North Korean IT workers can violate sanctions, as the Treasury Department’s Office of Foreign Assets Control has cautioned since 2022.
Third, the delivery method is the open-source software supply chain. Malicious npm packages spread through the same ecosystem that federal agencies and their contractors use to build software. Homeland411 reported on Sept. 21 that federal teams are already dealing with a record patch load under CISA’s new BOD 26-04. Malicious packages are harder to handle than ordinary vulnerabilities because there is no patch to apply, and the only defense is to stop developers from running the code in the first place.
The campaign is also different from other nation-state intrusions Homeland411 has covered, such as China’s Volt Typhoon living-off-the-land intrusions pre-positioned in utility networks. Those operations aim to stay hidden for long periods. WaterPlum works in volume and aims for quick payouts, and the advisory shows it has built capabilities useful for espionage along the way.
What Organizations and Developers Should Do
The advisory gives specific steps for both individual developers and the companies that hire or contract with them:
- Never run interview code on a real machine. Run unfamiliar code only in a sandbox or virtual machine, never on a device that holds cryptocurrency, credentials or client data. Before running any script, check it for obfuscated sections and for strings the advisory flags, including “curl,” “base64,” “-enc,” “mshta,” “Invoke-WebRequest” and “hidden.”
- Treat VS Code trust prompts as a security decision. Open unfamiliar projects in Restricted Mode by answering “No” to the “Do you trust the authors” prompt, and inspect any .vscode/tasks.json file before trusting a folder.
- Assume theft after any infection. Removing the malware is not enough. The advisory recommends moving all assets to a new wallet created on a separate device, storing the new seed phrase offline, and fully reinstalling the operating system.
- Verify remote hires more thoroughly. Check that applicants’ IP addresses match where they say they live, call the phone numbers they list, and verify certifications by registration number. Be wary of candidates who avoid meeting in person, ask to be paid in cryptocurrency or into someone else’s account, glance at another screen while answering, or have repeated video freezes.
- Check the whole contractor chain. Subcontractors further down the chain may be working with North Korean IT workers. The advisory recommends adding contract terms that address this risk and giving every contractor only the minimum access needed, following the least-privilege approach in the federal zero trust roadmap.
- Plant tripwires on developer credentials. Decoy credentials and tokens placed on developer machines can show when stolen access is used elsewhere. CISA recently issued its first dedicated guidance on cyber decoys.
- Report suspicions. The FBI asks U.S. companies that suspect a North Korean IT worker, or a contractor acting as a front for one, to report it to IC3 and to cut off that person’s accounts and sessions right away.
The advisory closes by warning that the techniques it describes “are only examples; actors continuously evolve and refine their methods.” Its figures show a regime that funds its weapons programs in part through job interviews and remote hiring, which gives recruiters, hiring managers and individual developers a direct role in defending against it. For more of Homeland411’s coverage of the regime, see our North Korea archive.
INTERNAL LINKS USED (Homeland411)
- Record Patch Load Puts CISA’s New BOD 26-04 Under Pressure
- CISA Issues First Dedicated Guidance on Cyber Decoys
- Interagency Advisory Details Pre-Positioned Living-off-the-Land Cyber Intrusions
- Intelligence Community Warns of Generative AI Integration in Asymmetric Cyber Operations
- OMB and CISA Release Federal Zero Trust Strategy Implementation Roadmap
- WMD Financing Elusive on International Playing Field
- North Korea category archive
SOURCES & REFERENCES (for editor verification / outbound links)
- Joint advisory (NPA, NCO, FBI, DC3, ASD’s ACSC, BND, BfV) – North Korean “WaterPlum” / Contagious Interview and IT Workers (Sept. 18, 2026)
- BleepingComputer – North Korean WaterPlum hackers infected 30,000 devices worldwide
- The Hacker News – Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- The Hacker News – Jade Sleet Linked to Indian IT Provider Breach (SentinelOne research)
- S. Department of Justice – Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote IT Worker Schemes
- Help Net Security – Helping North Korean IT remote workers is becoming a fast track to prison
- FBI IC3 PSA – North Korean IT Workers Conducting Data Extortion (Jan. 23, 2025)
- Treasury/State/FBI – Guidance on DPRK Information Technology Workers (May 16, 2022)
- Palo Alto Networks Unit 42 – original Contagious Interview research