North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews.
This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate AI, cryptocurrency, and NFT companies.
IC3 have reported that this operation has facilitated the theft of cryptocurrency funds and account credentials from more than 7,000 wallets, generating an estimated JPY 1.7 billion, approximately $10.71 million, for the Democratic People’s Republic of Korea (DPRK).
WaterPlum Hackers Target IT Professionals
WaterPlum operators reach out to victims via social media, job portals, freelance platforms, recruitment services, and online gig marketplaces.
They present enticing job opportunities, arrange virtual technical interviews, and request candidates to complete coding assignments. However, the interview process is actually designed to deliver malware.
Victims are instructed to download and run files claimed to be necessary for testing code, troubleshooting development issues, or resolving video-conferencing problems.
The attackers host these malicious files on software development collaboration platforms and code repositories, making them appear legitimate to tech-savvy targets.
In some instances, the threat actors reportedly used AI face-swapping software during video interviews. After several minutes, they would disable their video feed and encourage the candidate to do the same, citing connection difficulties.
The malicious packages employed in the campaign include known WaterPlum malware families, such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
- BeaverTail is JavaScript-based malware often concealed within npm packages.
- InvisibleFerret acts as a Python backdoor.
- OtterCookie combines remote access Trojan and infostealer capabilities, allowing attackers to maintain access while gathering sensitive data.
- StoatWaffle utilizes malicious Visual Studio Code projects and can execute code through project configuration files when a victim opens and trusts a repository.
Once it gains access, WaterPlum uses loaders, remote access tools, and information stealers to establish persistence and collect valuable data.
The stolen information may include browser credentials, cookies, clipboard content, screenshots, keystrokes, private keys for cryptocurrency wallets, seed phrases, and sensitive files stored locally or in shared directories.
Compromising a developer can create further risks, potentially granting access to the developer’s employer, customers, or ongoing projects. Authorities have warned that stolen credentials and access tokens could enable corporate espionage, intellectual property theft, additional lateral movement, and extortion.
Investigators have linked WaterPlum’s activities to DPRK IT-worker schemes that use laptop farms and virtual private servers to obscure workers’ actual locations.
These operations allow North Korean personnel to secure overseas contracts, impersonate legitimate workers, and funnel income through intermediaries.
Japanese authorities reported that WaterPlum and suspected North Korean IT workers used overlapping IP addresses to access laptop farms, crowdsourcing services, and job applications.
To protect against these threats, security teams should consider unsolicited interview code, npm packages, and shared development repositories as potential initial access vectors.
Developers should avoid running unfamiliar code on their primary workstations or on systems containing cryptocurrency assets. Unknown projects should be executed only in isolated virtual machines or sandboxes, and Visual Studio Code repositories should remain in Restricted Mode until configuration files, such as .vscode/tasks.json, have been thoroughly reviewed.
Organizations should also implement endpoint detection and response tools, enforce least-privilege access policies, monitor contractor activity, and quickly isolate potentially infected systems.
Victims of these attacks should rotate their credentials, migrate crypto assets to a new wallet created on a clean device, and rebuild compromised endpoints to eliminate persistent malware.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

