North Korean hackers turned the job interview itself into the attack, and a joint advisory from Japan’s National Police Agency and the FBI published September 18, 2026 details exactly how the scheme, tracked as WaterPlum or Contagious Interview, worked against software developers for seven months.
Between December 2025 and July 2026, the group built fake recruiter profiles on social media, job boards and freelance marketplaces, posing as headhunters for artificial intelligence, cryptocurrency and NFT companies. The targets were IT professionals and software developers. A candidate who took the bait was invited into a fraudulent job interview, or asked to complete a coding task, that was laced with malware.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the two agencies wrote in the joint advisory, which formally attributes the campaign to North Korea’s 313 General Bureau.
Once a machine was infected, the malware went straight for the tools a developer and a crypto user share. The programs hunt for browser passwords, screenshots and keystrokes, and they also take the secret keys that control a crypto wallet. The toolbox included strains called BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, according to the advisory.
The scale is large. The advisory counts more than 30,000 infected devices in over 100 countries and data taken from more than 7,000 crypto wallets, with wallets controlled by the group receiving at least 1.7 billion Japanese yen, roughly $10.71 million, during the campaign window.
For anyone job hunting in crypto, the pattern is the warning. A recruiter contact that arrives cold on LinkedIn, a freelance platform or a job board is the entry point, and the “assignment” stage of the process is where code runs on your machine. The advisory’s core detail is that the payload arrived through steps that look like ordinary hiring: an interview, a coding test, a task from a hiring manager. Earlier campaigns from the same group leaned on deepfake recruitment video calls to reach senior staff, investigators said, so the fake recruiter does not stop at text.
The practical takeaway is narrow: treat any code a prospective employer asks you to run as hostile until proven otherwise, and keep a wallet with meaningful funds on a machine that never touches hiring workflows.


