Contagious Interview: 30,000 devices infected by a fake job interview
Contagious Interview: 30,000 devices infected by a fake job interview 2026-9-22 06:44:46 Author: securityaffairs.com(查看原文) 阅读量:3 收藏

Contagious Interview: 30,000 devices infected by a fake job interview

Pierluigi Paganini September 22, 2026

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.

On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview. The name says it all. The job interview is the infection vector.

The numbers in the advisory are hard to shrug off. At least 30,000 devices infected across more than 100 countries, funds or credentials stolen from over 7,000 cryptocurrency wallets, and a total of 1.7 billion yen, roughly $10.71 million, funneled back to North Korea. The victims are almost always the same type: freelance developers and specialists in blockchain and Web3 work.

Japan’s NPA and the FBI assess that both WaterPlum operators and some North Korean IT workers report to the same place, the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party’s Central Committee. That’s not a loose affiliation. It’s an org chart.

The trap itself is almost embarrassingly simple. WaterPlum actors pose as recruiters or hiring managers, often impersonating real AI, crypto, or NFT companies, and reach out on social media, job boards, and freelance platforms. Candidates get invited to a technical interview, then told to download a file to complete a coding test or fix a supposed bug on the video call.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities. They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.” reads the joint advisory. “WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).”

That file is never what it claims to be. The advisory names five malware families riding inside these downloads, BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, each doing its own piece of the job: one steals browser credentials, another opens a backdoor, another sets up a remote access trojan to move deeper into the machine. Once inside, the goal is straightforward: drain the wallet, then look for whatever else might be worth stealing.

What happens next goes beyond one stolen wallet. The report notes that a successful infection can give WaterPlum a way into the victim’s employer, opening the door to espionage, stolen source code, and further movement inside a company’s systems. Stolen ID photos get reused too, letting North Korean IT workers impersonate the victim to land more paying contracts elsewhere.

That last part connects to a separate but related scheme covered in the same advisory: North Korean IT workers using so-called “laptop farms.” These are physical locations, often just someone’s house, where a local facilitator plugs in company-issued laptops and lets a North Korean worker operate them remotely over VPN. The worker gets a Western-looking identity and a legitimate-sounding job. The facilitator gets a cut.

“Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments. Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency.” continues the report. “Other sensitive data targeted for exfiltration includes:

  • Authentication data stored in web browsers (ID, password, etc.);
  • Clipboard information, key-logs (recorded keystrokes), screenshots;
  • Cryptocurrency-wallet data (private key, seed phrase, etc.); and
  • Any files or data of interest to the actors on a PC or in shared folders (ID pictures of driver’s licenses, passports, etc.)”

Here’s a simpler and more natural version, while keeping the same details:

Japan says this is no longer just a theoretical threat. Authorities have already shut down the country’s first known “laptop farm,” run by a local facilitator who had moved several hundred million yen in cryptocurrency out of Japan. In the US, the FBI says it continues to prosecute people who help North Korean IT workers operate this way, across several states and under different charges.

The advisory also describes a case involving a Japanese crypto exchange that spotted one of these applicants in May 2025. His resume listed an unusually wide range of skills across more than a dozen technologies. He claimed to be Malaysian, raised in Finland, and fluent in Malay and Chinese, but struggled with basic English questions that did not fit his claimed background. The company rejected him, avoiding any damage.

Other red flags recruiters have picked up on read like a checklist for a bad Zoom call: the applicant glancing sideways as if reading a script, background voices that shouldn’t be there, video that keeps freezing at convenient moments, a firm preference for getting paid in crypto, sometimes to someone else’s account entirely.

Not every North Korean IT worker sticks to quiet fraud, either. One extorted a client over a payment dispute and leaked the company’s proprietary code online out of spite. Another, hired for basic website maintenance, defaced the site and knocked it offline instead. Petty, but the effect on the client was anything but.

The advisory draws one more thread together: WaterPlum’s cyberattack operators and North Korea’s IT worker network aren’t running in parallel. They’ve been caught using the same IP addresses to access laptop farms, register on freelance platforms, and apply for that same crypto exchange job. Same infrastructure, two revenue streams, one regime cashing the checks.

“The techniques described in this advisory are only examples; actors continuously evolve and refine their methods.” concludes the advisory. “Stay informed by monitoring alerts from domestic and international security agencies and by reviewing reports published by security vendors.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – Contagious Interview, WaterPlum)




文章来源: https://securityaffairs.com/199506/uncategorized/contagious-interview-30000-devices-infected-by-a-fake-job-interview.html
如有侵权请联系:admin#unsafe.sh