WaterPlum NK
The FBI Cyber Division publicly flagged WaterPlum as an active threat, warning IT professionals globally to exercise caution when approached with unsolicited job offers online DC Studio/Magnific

A North Korean state-linked cyber group has transferred the equivalent of $10.71 million in cryptocurrency to North Korea after targeting IT professionals in more than 100 countries through fake job interviews, according to a joint advisory from US, Japanese, Australian and German authorities.

The group, known as 'WaterPlum' and commonly referred to as 'Contagious Interview', was the subject of the advisory published on 18 September 2026 by the FBI, Japan's National Police Agency and National Cybersecurity Office, and the US Department of Defense Cyber Crime Center.

It was also issued by Australia's Australian Signals Directorate's Australian Cyber Security Centre, and Germany's Federal Intelligence Service and Federal Office for the Protection of the Constitution.

How the Scam Works

WaterPlum operatives target software developers, web freelancers, and professionals working in cryptocurrency and IT through job platforms, social media, and freelance marketplaces, presenting themselves as representatives of artificial intelligence, NFT, or cryptocurrency companies.

Candidates who reach the interview stage are then directed to download files or execute code as part of a supposed technical test, with those files carrying malware.

To appear convincing on video calls, WaterPlum actors use AI face-swapping technology to disguise themselves as employers. After a few minutes into the call, they may disable their video feed and advise the victim to do the same because of network issues, limiting how long the victim can scrutinise their appearance.

The malicious software embedded in these interview files, including the strains the advisory identifies as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, provides attackers with backdoor access to victims' computers.

From there, they extract cryptocurrency wallet credentials, browser-stored authentication data, keystrokes, screenshots, and identity documents including passport scans, while stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency.

The advisory also documents cases involving North Korean IT workers who obtained contracts through freelance platforms and later engaged in malicious activity, including extortion. In one instance, a worker engaged for website maintenance deliberately defaced the hiring company's site and rendered it entirely inaccessible following a payment dispute.

The Scale of the Operation

From around December 2025 through July 2026, WaterPlum exploited at least 30,000 PCs across more than 100 countries. The actors transferred funds or account credentials from more than 7,000 cryptocurrency wallets during that period.

The actors transferred 1.7 billion Japanese yen, equivalent to about $10.71 million, in cryptocurrency assets to the Democratic People's Republic of Korea. The FBI said the threat remains active, urging IT professionals to treat unsolicited job approaches with heightened caution.

The FBI and Japan's National Police Agency assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is subordinate to the Central Committee of the Workers' Party of Korea.

Warning Signs and What To Do

The advisory identifies several indicators that an online recruiter or prospective worker may be connected to North Korean IT operations, including an unusually broad skill set, requests for payment in cryptocurrency, reluctance to attend in-person meetings, and repeated audio or visual disruptions during calls.

IT professionals should also take precautions when handling files or code received during a recruitment process.

Any such code should be executed only inside a sandbox or virtual machine, and never on a device that holds personal data or digital asset wallets. For businesses commissioning work through freelance platforms, the advisory cautions that subcontractors further down the chain may have links to North Korean IT workers without the company's knowledge.

It says paying North Korean IT workers or facilitating their foreign-currency activities may violate domestic laws and sanctions against North Korea.

The US Treasury's guidance on North Korean IT workers similarly warns of potential legal and sanctions consequences for individuals and entities involved in or supporting such activities.

The WaterPlum advisory builds on a pattern of malicious activity involving North Korean IT workers.

A January 2025 IC3 alert warned that North Korean IT workers had extorted companies by holding stolen proprietary data and source code hostage until ransom demands were met, while the latest advisory documents additional cases involving website defacement and other malicious activity.

As remote hiring and freelance contracts become increasingly routine across the technology sector, the methods used by WaterPlum demonstrate how recruitment processes can be exploited to gain access to individuals and organisations.