
The interview begins like a normal piece of remote technical hiring. Someone who appears to represent an AI or blockchain company contacts a developer. There is a coding exercise, a project repository, perhaps a troubleshooting step during a video call. The candidate wants the job, so the candidate opens the project. That is the moment the job interview changes sides: the employer is fictional, and the assignment is a delivery vehicle.
A September 18 joint advisory from Japanese, American, Australian and German authorities calls the operation WaterPlum, also widely known as Contagious Interview. The agencies say the North Korean actors infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026. They report funds or credentials taken from more than 7,000 cryptocurrency wallets and at least 1.7 billion yen, about $10.71 million, transferred in cryptocurrency assets to North Korea. These are the agencies' investigative figures, not an independent Cyberdelia census of every infection.
The size of the campaign matters. Its design matters more. A developer can be a victim in the morning, an access path into a company after lunch, and the unwitting source of an identity document used to hire an entirely different North Korean worker next month. The operation turns the conventions of remote hiring into infrastructure for theft, persistence and impersonation.
The test is the payload
Ordinary recruitment already asks applicants to do risky things: open unfamiliar links, run sample code, install dependencies, clone repositories and demonstrate that they can troubleshoot quickly while somebody watches. The advisory describes WaterPlum actors recruiting through social platforms, job sites and freelance marketplaces, then asking applicants to download and execute files during an interview or coding assignment. An error in a video call can also become the pretext for a download. The attack does not need to invent a suspicious new ritual. It borrows one that the industry has normalized.
Investigators list several malware families associated with the operation, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. The names are less useful to a reader than the delivery pattern. A repository or package may contain code that runs when the candidate installs dependencies or trusts a project in an editor. Once launched, a loader can bring in remote access tools and information stealers. The advisory specifically warns that a malicious Visual Studio Code project can hide an executable task in .vscode/tasks.json. The project's apparent purpose is an interview. Its actual purpose can be to make the applicant's own workstation execute somebody else's instructions.
That workstation is an attractive target. Developers often store source code, cloud sessions, browser credentials and access to workspaces on the same machine used for job hunting. Crypto specialists may also handle wallet software or sensitive keys. The agencies describe theft of browser authentication data, clipboard contents, screenshots, files, identity images and wallet material. They also describe remote access that can persist after the first theft. A candidate who lands a real job later may carry the compromise into a new environment.
A criminal supply chain built out of careers
The advisory connects WaterPlum to a related North Korean revenue scheme: workers who obtain real contracts or employment by using false identities and remote computer setups. It says Japanese investigators dismantled a laptop farm operated by an enabler in Japan, and identifies overlapping IP addresses used for laptop farms, crowdsourcing and applications to a Japanese cryptocurrency exchange. The authorities assess that WaterPlum actors and some IT workers operate under the same North Korean bureau. That is an attribution by the named agencies; it should be read as their finding, not as a claim that every person in a remote interview is part of one centrally run crew.
The overlap creates two routes to the same business. One route is an outside attacker using a fake opening to infect a legitimate applicant. The other is a disguised worker obtaining an actual company account and salary. Stolen IDs can help the second route. An infected applicant who later gains legitimate access can extend the first. The business does not have to fail its security review in one spectacular moment. It can be entered through a sequence of ordinary personnel and endpoint decisions.
AI appears in this campaign as practical camouflage, not as a mystical autonomous hacker. The advisory says actors have used face swapping in interviews, text to speech for pronunciation practice, translation services and attractive AI company identities. None of that proves a model conducted the compromise. It shows how cheap tools make an international hiring persona easier to maintain and harder to judge from a single call. A blurry webcam or a polished résumé cannot establish who controls the machine on the other end.
What a useful defense actually tests
For an applicant, the important boundary is between reading an assignment and executing it. A recruiter may be real and still send unsafe code; a real company may have a compromised repository. Unknown projects belong in a constrained environment, with personal wallets, cloud credentials and normal work sessions kept out of reach. Review installation scripts and editor tasks before running them. Visual Studio Code's Restricted Mode matters because a trusted project can trigger behavior that a quick glance at source files misses. An isolated environment is useful only if it cannot reach the secrets the attacker wants.
For an employer, this cannot be reduced to guessing accents or policing faces on video. Those cues are weak, easy to misuse, and the advisory's examples are observations from investigations rather than a reliable identity test. Verify claimed work, certifications and employment details through independent channels. Provision access in stages. Give contractors the smallest rights needed and log what their accounts actually do. Treat an employee's personal device as a possible source of stolen credentials, even if the employee has done nothing wrong.
If a machine may already be infected, removing a suspicious package is not proof that stolen wallet keys or sessions are safe. The advisory advises isolating the affected device, treating exposed credentials as compromised, moving crypto assets to a wallet created on a clean separate device and rebuilding a machine where persistence is plausible. The immediate question is what could have been taken before the alert, not whether the malicious process is still visible.
The counterintuitive risk to the next employer
The hiring company may never speak to the fake recruiter. That is what makes the spillover so hard to notice. Suppose a developer uses a personal machine to complete a malicious assignment, then later joins a legitimate team. If the attacker retained a remote foothold or took browser sessions and identity material, the boundary around the employer now depends on how access is provisioned, whether old personal sessions are reused and whether the device's history is known. The advisory calls follow-on infiltration an opportunity, not a measured count of corporate compromises. That distinction should shape the response: investigate pathways without declaring every later employer breached.
There is a useful control principle here. Employers should provision a fresh account and managed endpoint, keep development secrets out of personal browsing profiles and require explicit approval before a contractor can reach production data. Those steps are useful regardless of whether a particular applicant was deceived. They also avoid making the victim responsible for an entire organization's security merely because the attacker chose a fake recruiting approach.
Software teams should review what a sample project can execute before deciding how realistic a coding test must be. If the company genuinely needs candidates to run code, it can offer a controlled browser environment or a disposable workspace instead of instructing applicants to trust an arbitrary repository on their own machines. That protects the company from copying an unsafe hiring practice and makes a legitimate opportunity easier to distinguish from a trap.
Where the numbers stop: method and limits
The reported 30,000 devices do not tell us how many corporate networks were reached. The 7,000 wallet figure joins stolen funds and credentials in the advisory's wording; it is not a verified count of seven thousand emptied wallets. The $10.71 million figure is a reported transfer amount within the authorities' investigative scope, not an estimate of all damage to every affected company. Nor does an overlapping IP address alone prove that two named operations share every operator or objective. The agencies draw a broader conclusion using their combined investigations, some of which remain undisclosed.
Those limits do not weaken the central mechanism. The attacker first gets the prospective employee to perform the setup work. The applicant's ambition supplies urgency; the development tools supply execution; a future employer can supply the next set of permissions. The interview is no longer merely where a company checks a person. It is also where a person must check the company.
WaterPlum makes remote hiring an attack surface that crosses personal devices, package ecosystems, wallet custody and corporate identity. A credible defense needs a clean execution boundary for applicants and measured permissions for employers. A résumé, a video call and a coding test cannot substitute for either.
Source trail and method
Joint NPA, NCO, FBI, DC3, ASD, BND and BfV advisory, September 18, 2026 (PDF). Figures and tactics come from the joint advisory. Cyberdelia's discussion of hiring and endpoint boundaries is analysis of the described mechanism.

