The security authorities from the USA, Japan, Australia, and Germany jointly warn about the North Korean hacker group Waterplum, which poses as an AI company during job interviews. According to the warning published on September 18, the group has infected at least 30,000 computers in over 100 countries since December 2025 and has stolen cryptocurrency worth nearly eleven million dollars.
Fake Job Interviews Spread Malware
Waterplum – also known as Contagious Interview – specifically targets victims through social networks, job boards, and freelancer platforms. According to the joint warning from the FBI, Japanese police, the Australian ASD, and the Federal Intelligence Service and the Office for the Protection of the Constitution, the perpetrators pose as recruiters for AI, crypto, or NFT companies. In the application process, candidates are asked to solve a technical task or fix a supposed bug in a video conferencing software. For this, they download a prepared file disguised as part of the programming task.
The malicious files are hidden in manipulated Node Package Manager packages and contain malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. The packages are also distributed via GitHub and Bitbucket, where they masquerade as harmless developer tools. Once the backdoor is active, the attackers install remote access trojans and info stealers that capture login credentials, clipboard contents, keystrokes, and especially cryptocurrency wallets. Individual web developers and professionals in blockchain and Web3 technologies are particularly affected. According to authorities, the perpetrators have already plundered over 7,000 cryptocurrency wallets between December 2025 and July 2026.
North Korean IT Forces Operate Laptop Farms Abroad
Some members of Waterplum work simultaneously as regular IT staff for foreign clients – under false identities. This is made possible by so-called laptop farms: company computers are located in the homes of local helpers, who technically obscure access from North Korea, China, or Russia. The helpers receive salary payments to their own accounts and forward the money, while stolen identification photos are used for identity deception.
Japan reports what it claims is the first successfully dismantled case of such a laptop farm. The Japanese police noted the transfer of several hundred million yen in cryptocurrency, as reported by the Japanese Ministry of Foreign Affairs. In the USA, the FBI is simultaneously pursuing accomplices who help North Korean IT forces with their camouflage. Some incidents went beyond mere revenue generation. In one case, a planted IT employee extorted his client and published their source code. In another case, he took down the company website after being terminated. Investigators also found identical IP addresses in Waterplum attacks and applications from the IT forces – evidence of the close interconnection of both activities.
Authorities Name Specific Warning Signs for Recruiters
The report lists anomalies that can already be recognizable during the job interview:
- Applicants avoid personal meetings.
- They insist on payment in cryptocurrency.
- They repeatedly glance at a second screen during the video call.
- The image or sound freezes noticeably often.
At a Japanese cryptocurrency exchange, a candidate’s resume and language skills were clearly inconsistent; the company rejected him before any damage occurred. Similar patterns were already exhibited by the North Korean group Kimsuky, which operates its own offline AI environment for phishing campaigns.
For IT professionals themselves, authorities recommend not executing code from unknown clients without verification, but rather testing it first in a sandbox or virtual machine. VS Code projects from unclear sources should only be opened in restricted mode, which blocks automatic script execution. Additionally, investigators advise companies to use endpoint detection and response software. If there is suspicion of an already occurred infection, the affected device should be immediately disconnected from the internet, and a new crypto wallet should be created on a separate device.
It will be crucial whether companies secure their hiring processes technically, as the mentioned warning signs can be recognized with simple checks before an application even leads to a video call. It remains unclear how severely Germany and other European countries are already affected. The current report documents specific cases mainly from Japan and the USA. However, the fact that the Federal Intelligence Service and the Office for the Protection of the Constitution are appearing as co-signers for the first time suggests that Waterplum is also spreading to Europe.


