Japan, the United States, Australia and Germany, today issued a joint cybersecurity advisory formally attributing the long-running “Contagious Interview” campaign to a North Korean state-sponsored group they are calling WaterPlum. The operation has infected more than 30,000 computers in more than 100 countries and stolen about 1.7 billion yen, or some $10.7 million, in cryptocurrency.
The advisory carries the seals of Japan’s National Police Agency and National Cybersecurity Office, the FBI and the U.S. Defense Department’s Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre and Germany’s BND and BfV intelligence services. It places WaterPlum under the 313 General Bureau of North Korea’s Munitions Industry Department, which oversees weapons production — framing the theft as state revenue generation rather than ordinary cybercrime.
Also read: US, Japan, South Korea Meet Private Partners to Combat North Korea’s IT Work Fraud Scheme
The tradecraft is unusual in that the victims are individuals, not enterprises. Operators pose as recruiters for AI, cryptocurrency and NFT companies, approaching developers, web designers and blockchain specialists via social media, job boards and freelance marketplaces.
At the technical-interview stage, the candidate is asked to run a coding assignment or troubleshoot a video-conferencing problem. Either pretext delivers malware, typically via malicious Node Package Manager packages hosted on GitHub or Bitbucket. The agencies describe the objective as infiltrating “unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency.”
Five malware families are named. BeaverTail, a JavaScript infostealer hidden in npm packages; InvisibleFerret, a Python backdoor; OtterCookie, a JavaScript remote access trojan with stealer functions; OtterCandy, which blends OtterCookie with a family called RATatouille; and StoatWaffle, a modular Node.js loader bundling credential harvesting and a RAT.
Together they siphon credentials, clipboard contents, keystrokes, screenshots, wallet keys and seed phrases, identity documents and source code. Japanese police put the most intense phase between December 2025 and July 2026, with roughly 7,000 cryptocurrency wallet cases recorded.
Also read: Don’t Fall for the Fake Job! FBI Warns of Work-From-Home Scams Using Cryptocurrency
The advisory pairs the campaign with North Korea’s remote IT worker scheme, treating it as the same revenue apparatus seen from the employer’s side. Operatives use stolen identity documents and virtual private servers to obscure their locations, working from North Korea, China, Russia, Africa and Southeast Asia, while “laptop farms” in facilitators’ homes supply plausible in-country IP addresses. Where placements sour, the agencies say the workers have turned to extortion over payment disputes, website defacement and publication of stolen source code. Japanese investigators dismantled one domestic laptop farm and traced several hundred million yen abroad.
Guidance for practitioners is that run untrusted interview code only in a virtual machine; treat commands containing curl, base64, -enc, mshta or Invoke-WebRequest with suspicion; open unfamiliar projects in Visual Studio Code’s Restricted Mode and inspect .vscode/tasks.json first; and after any infection, assume credentials are lost, rotate wallets from a clean device and reinstall the operating system. Employers are told to check applicant IP addresses against claimed locations and to watch for refusal to meet in person, frequent audio and video freezes, or use of face-swapping software.
Also read: North Korean Cyber Fraud Scheme Targets U.S. Firms, DOJ Indicts Five Individuals
The compliance exposure is significant. The U.S. State Department issued an alert to companies on North Korean IT workers in July, and the Justice Department has prosecuted facilitators and seized laptop farms. Firms that unknowingly pay a North Korean contractor risk sanctions liability, which is why the advisory pushes contractual controls and identity verification, not detection alone. Japan’s Foreign Ministry said it would “strengthen its efforts with the ally and like-minded countries and the private sector.”
What to watch: whether the attribution is followed by sanctions designations, how npm and code-hosting platforms respond to package delivery at this scale, and whether the ACSC issues Australia-specific guidance for contractor and Web3 employers.






































