Fake interviews exploited at least 30,000 PCs in eight months, and the wallets were the cheap part
Seven agencies in four countries say North Korea's WaterPlum group exploited at least 30,000 PCs in more than 100 countries between December 2025 and July 2026, through fake job interviews. The cryptocurrency taken works out at about 357 dollars a machine, which tells you what was really collected.
By Parminder Kumar Sharma · · 19 min read

What 357 dollars a machine tells you
On 18 September 2026 seven bodies across four countries published a joint advisory on a North Korean operation they call WaterPlum, the group most vendor reporting knows as Contagious Interview. The signatories are Japan's National Police Agency and National Cybersecurity Office, the US Federal Bureau of Investigation and the Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's Federal Intelligence Service and Federal Office for the Protection of the Constitution.
Three numbers carry the story. At least 30,000 PCs exploited in more than 100 countries. Funds or account credentials taken from over 7,000 cryptocurrency wallets. At least 1.7 billion Japanese yen, which the advisory gives as 10.71 million US dollars, moved to the DPRK.
Do the division the advisory does not do. Ten point seven one million dollars across thirty thousand machines is about 357 dollars per exploited PC. Seven thousand wallets across thirty thousand machines is roughly one wallet for every four PCs. A state directed operation ran for about eight months, reached more than a hundred countries, and averaged the price of a mid range phone per compromised machine.
That is the fact worth sitting with before anything else. Either this is an unusually inefficient state operation, or the cryptocurrency was never the whole point.
What the figure measures, and what it leaves out
The 30,000 appears in section 4 of the advisory, under the heading "NPA Information on Scale of Malicious Activity". The exact sentence is that "From around December 2025 through July 2026, WaterPlum exploited at least 30,000 PCs in over 100 countries".
Read that carefully, because a lot of coverage has flattened it into "infected 30,000 devices" and lost three qualifiers.
It is a police figure, attributed to Japan's National Police Agency, not a vendor telemetry count. The advisory says the tactics were discovered by the National Cyber Department of Japan's Kanto Regional Police Bureau, relevant prefectural police, the FBI, and through information sharing with private sector partners. It does not say whether the 30,000 came from seized command and control infrastructure, from log analysis in the laptop farm investigation, from partner telemetry, or from some combination. The counting method is simply absent.
It counts PCs, not people. A developer with a laptop and a desktop is two. A machine reimaged and reinfected may be two. The advisory does not say the count was deduplicated to individuals, and there is no reason to assume it was.
The period start is fuzzy in the advisory's own words: "from around December 2025". If you take the widest reading, 1 December 2025 to 31 July 2026 is 243 days, which puts the average at about 123 PCs a day, every day, for eight months. That is our arithmetic on the advisory's floor figure, and the word "around" means it should be read as an order of magnitude, not a rate.
One more thing hides in the dollar figure. The advisory states 1.7 billion JPY and glosses it as 10.71 million USD, which implies a rate of about 158.7 yen to the dollar. It does not say when that rate was taken, and the yen figure is itself a floor. So the dollar number inherits two uncertainties: the floor, and an undated conversion. It is the number every headline used.
What the joint advisory of 18 September 2026 states about scale, and what it leaves unstated. Drawn from sections 1 and 4 of the advisory text.
| Stated in the advisory | Not stated in the advisory |
|---|---|
| At least 30,000 PCs exploited, from around December 2025 through July 2026 | How the count was derived, or whether devices were deduplicated to individual people |
| More than 100 countries, including Japan and the United States | Any breakdown by country. The words United Kingdom do not appear in the document |
| Funds or account credentials taken from over 7,000 cryptocurrency wallets | How many distinct victims those wallets belong to |
| At least 1.7 billion JPY, given as 10.71 million USD | The date or source of the exchange rate behind that conversion |
| Primary targets were web designers, engineers and cryptocurrency, blockchain and Web3 specialists | Whether the exploited machines were personal or employer issued |
| A laptop farm in Japan identified, investigated and dismantled for the first time | How many laptops it held, or how many of the 30,000 relate to it |
The lure, step by step
The mechanism is not subtle, and it does not need to be. According to the advisory, WaterPlum actors recruit job seekers internationally through social media platforms, online job platforms, gig work platforms and freelance marketplaces, impersonating legitimate AI, cryptocurrency or NFT companies, and they have also used recruiting services. Then they require the job seeker to take part in a technical online virtual interview or complete a technical coding assignment.
The delivery step is one sentence in the advisory and it is the whole story: during interviews, the actors "instruct job seekers to download and execute malicious files, hosted on multiple online collaboration software developer platforms and code repositories, to complete a coding assignment or troubleshoot an error in the online video conferencing platform."
Two pretexts, and they are worth separating because they defeat different instincts.
The first is finish this exercise. It exploits the candidate's willingness to work. Running the take home task is the job application.
The second is your video is not working, run this fix. It exploits time pressure inside a live call with someone who appears to hold the offer. This is the ClickFix pattern applied to a job interview, and NTT Security Japan tracks a related WaterPlum sub campaign under the name ClickFake Interview.
From there it is conventional. The advisory says the actors upload malicious Node Package Manager packages carrying BeaverTail, InvisibleFerret, OtterCookie, OtterCandy or StoatWaffle and related variants. Once a loader gives them backdoor access they use remote access trojans for connectivity, persistence and pivoting, and infostealers to send data to a command and control address.
No vulnerability is exploited at any point in that chain. The candidate is the exploit.
The one family that deserves a second read is StoatWaffle, which the advisory describes as a modular Node.js family combining a loader, credential harvesting components and a RAT, delivered through malicious Microsoft Visual Studio Code projects. It uses blockchain themed project repositories as decoys and embeds a malicious VS Code configuration file "that triggers auto-run code execution when the folder is opened and trusted by the victim."
Opened and trusted. Not run. Not built. Opened.
Why a developer's own machine is the prize
The advisory lists what gets taken. Authentication data stored in web browsers. Clipboard contents, key logs and screenshots. Cryptocurrency wallet data, including private keys and seed phrases. And, in the advisory's own wording, "any files or data of interest to the actors on a PC or in shared folders", with driving licence and passport photographs called out explicitly.
Now put that against the arithmetic. Roughly three quarters of those 30,000 machines produced no drained wallet. They produced the rest of the list.
The advisory is unusually direct about what the rest of the list is for. It says successful infections give the actors "opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments." And it says stolen ID images "can also be used by North Korean IT workers to impersonate victims and generate foreign currency.
That second sentence closes a loop that most of the coverage has missed entirely. The advisory covers two things that look like separate stories: WaterPlum robbing developers, and North Korean IT workers fraudulently getting hired through laptop farms. Section 5 joins them in a single paragraph: WaterPlum actors and North Korean IT workers "used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange."
So the identity documents stolen from a developer in one half of the advisory are, on the agencies' own account, the raw material for the impersonation in the other half. The victim of the fake interview becomes the cover story for the fake employee. That is the most consequential line in the document and it is nine words of IP address correlation.
The friendly name is not a control
Two comforting labels are doing real damage here.
The first is coding assignment. It is a hiring word. It carries an entire social contract: this is a normal stage, everyone does it, refusing looks difficult. What it actually describes, in this campaign, is arbitrary code execution by an unverified stranger on the candidate's own machine. The hiring word supplies all of the social pressure and none of the control.
The second is the trust prompt. Every developer has seen "Do you trust the author of the files in this folder?" and most treat it as the control that stands between a downloaded repository and their machine. The advisory's own mitigations show two ways past it, and the second is the one worth pinning to the wall.
The advisory tells readers to open unknown VS Code projects in Restricted Mode, which it explains means answering "No" to the trust prompt, and it notes that Restricted Mode prevents execution of .vscode/tasks.json on launch. It tells readers to verify the contents of any .vscode/tasks.json file in Restricted Mode or another editor for code that downloads or executes additional files.
Then it adds this: "Avoid opening unknown projects in VSCode from a folder or file path you have previously marked as trusted."
That is the gap. Workspace trust is inherited by path. If a candidate clones the interview task into the directory where they keep all their code, and that directory was marked trusted months ago, the prompt never appears. The control everyone is relying on does not fire, and nothing tells them it did not fire.
The real control is not the prompt. It is where you put the folder, which is a habit, not a product.
No employer control applies here
This is the part that should interest a UK security lead more than the dollar figure.
The target of this campaign is an individual doing something that looks exactly like ordinary work. Reading a specification. Cloning a repository. Running a build. Joining a video call. Every action in the chain is indistinguishable from a normal Tuesday, which is why no behavioural rule catches it.
And the machine it happens on is almost never yours. A candidate between jobs has no mobile device management, no endpoint detection, no single sign on logging and no security team to ring. A candidate who is currently employed runs their job hunt on personal kit deliberately, because running it on the company laptop is the one thing everybody knows not to do. Either way, the single moment when a developer is most likely to execute a stranger's code is the moment when every enterprise control is switched off by design, by the developer, for sound reasons.
This is the same gap our CHOSEN BRICK briefing described on 16 September, where an Iranian operation's documented fallback, once the managed device held, was to ask the target to open the file on a personal one. The difference here is that nobody has to ask. The personal device is where the entire interaction already lives.
Who counted, and who benefits from the count
Method and accusation should be kept apart, so three observations.
The attribution to the North Korean state is presented as an assessment, not as evidence. The advisory says the NPA and FBI "assess" that both WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers Party of Korea. That is a specific and unusually granular claim, and the document presents nothing underneath it. This is normal for a joint law enforcement advisory. It is still an assessment.
The advisory is Japan led. The scale figure is an NPA figure, the laptop farm case is a Japanese case, the recruitment case study is a Japanese cryptocurrency exchange, and both acknowledged private sector contributors are Japanese. Two of the seven signing bodies are German intelligence services, which suggests the German contribution sits on the IT worker half rather than the count. That last point is inference.
The acknowledged contributors have commercial interests, and saying so is not a criticism. NTT Security Japan named OtterCookie and OtterCandy, coined the WaterPlum label, and sells detection and SOC services into exactly this problem. bitFlyer is a Japanese cryptocurrency exchange with an obvious interest in the sector being seen to act. Both appear to have given genuine investigative help; both also benefit from the advisory existing. Read the numbers with that in mind, and then use them, because nobody else has better ones.
Does any of this touch the UK?
Directly, on the record, no. We searched the full nine page advisory. The words United Kingdom do not appear in it. No British agency signed it, the National Cyber Security Centre is not among the seven bodies, and no UK victim, sector or figure is named.
Indirectly, almost certainly yes, and the advisory will not help you say so. "More than 100 countries" with primary targets described as web designers, engineers and cryptocurrency, blockchain and Web3 specialists does not plausibly exclude a country with the UK's developer population. But that is a reasonable reading, not a stated fact, and we will not dress it as one.
What the UK does have points in the opposite direction. HM Treasury's Office of Financial Sanctions Implementation has published an advisory on North Korean IT workers which assesses it is "almost certain" that UK firms are being targeted by DPRK IT workers disguised as freelance third country workers, and which sets out red flags for hiring and the sanctions exposure that follows from paying one.
That advisory is written for the firm doing the hiring. It treats the UK organisation as the dupe. The WaterPlum advisory is written about the individual being hired, and treats the UK developer as the victim. A security lead who reads only UK guidance on this threat gets one half of it.
The two halves of the same operation, and which advisory covers each. Comparison drawn from the joint advisory of 18 September 2026 and the OFSI advisory on North Korean IT workers.
| Half of the operation | Who is the victim | Where UK readers find guidance |
|---|---|---|
| DPRK IT workers fraudulently hired through laptop farms and freelance platforms | The employer, plus its sanctions exposure | OFSI advisory on North Korean IT workers, written for hiring firms |
| WaterPlum robbing job seekers through fake interviews and coding tasks | The individual developer, on a personal device | Not covered by any UK advisory we could find, and no UK victim named in the joint advisory |
| The join between the two, where stolen ID photographs become an IT worker's cover | Both, sequentially | Stated only in section 5 of the joint advisory, as shared IP addresses |
Indicators a defender can act on
The advisory carries no hashes, no domains and no IP addresses. What it gives instead is a named family list, a set of command strings, and a behavioural profile, all of which are usable without any of this becoming a weaponisation guide.
Malware families named in the joint advisory of 18 September 2026, with the advisory's own footnote descriptions.
| Family | What the advisory says it is | Delivery noted |
|---|---|---|
| BeaverTail | JavaScript malware hidden inside npm packages | Downloadable from GitHub or Bitbucket |
| InvisibleFerret | A Python based backdoor into the victim's network | Follows a loader stage |
| OtterCookie | A JavaScript remote access trojan and infostealer | Malicious npm package payload |
| OtterCandy | Combines the features of OtterCookie and RATatouille | Malicious npm package payload |
| StoatWaffle | Modular Node.js loader, credential harvester and RAT | Malicious VS Code project, auto runs on folder trust |
The advisory asks readers to be especially cautious of commands or scripts containing the following strings, and to avoid running them unless the behaviour is fully understood. These are worth putting in front of anyone at your organisation who takes technical tests, and worth adding to a review checklist for any repository handed over during an interview process.
curl
base64
-enc
mshta
Invoke-WebRequest -uri
iwr -uri
hidden
There is also a behavioural profile, drawn from the agencies' observation of WaterPlum members, that is more useful to a hiring manager than any file hash:
- Online interviews conducted using AI face swapping software, with the actors disabling their video after a few minutes and advising the target to disable theirs, citing network problems.
- Activity dropping on North Korean public holidays, when the operators played games and watched football videos instead.
- Japanese pronunciation practised with text to speech software.
- Consistent use of free plans on machine translation and AI services.
And from the Japanese exchange's May 2025 case, the resume profile: an implausibly wide skill set, more than ten items of claimed knowledge and experience across programming languages, blockchain and cloud; education at a European university followed in quick succession by work in various European and Asian cities; and English ability that did not match the claimed background, so the applicant could answer simple questions but could not speak to most of the listed skills. The company declined to hire and recorded no damage.
What to do, in the order worth doing it
Take this with you
What a developer should never do in an interview process
- Never run an interview task on the machine that holds your work repositories, cloud credentials or password manager. Use a disposable virtual machine, or a machine you would happily wipe.
- Never accept the fix your video with this script pretext. No legitimate process requires you to execute anything to join a call.
- Never open an unknown project folder in VS Code inside a directory path you have already marked as trusted. Clone to a fresh, untrusted path.
- Never open first and read after. Read the .vscode/tasks.json file and the package.json scripts in a plain text editor before the folder goes anywhere near an IDE.
- Never run the install step a task instructs you to run without knowing what it pulls, even when the instruction is as ordinary as npm install.
- Never keep a wallet, a seed phrase or a photograph of your passport or driving licence on the machine you use for interview tasks.
- Never treat the company being real as evidence that the recruiter is. The advisory states the actors impersonate legitimate AI, cryptocurrency and NFT companies.
Take this with you
What an employer can offer, in the order worth doing
- Publish a one line hiring policy and put it in the first recruiter email: no stage of our process asks a candidate to run code we send them on their own machine.
- Where a coding exercise is genuinely needed, host it. A browser based IDE, a hosted sandbox, or a repository the candidate reads and discusses rather than executes.
- Offer a disposable environment to candidates who want one, before the technical stage rather than after an incident. A throwaway VM image or a funded cloud sandbox costs less than a compromised joiner.
- Tell your own engineers the same thing about their own job hunting, and say it without implying they should not be job hunting. The victims in this advisory are individual professionals; so are your staff.
- Add the case to onboarding. A new hire's personal machine may already be compromised before day one, so issue credentials to managed devices only and make the first push come from a managed device.
- Treat anyone who reports an interview infection as a reporter and not a suspect. You want that phone call to happen on day one rather than after the first commit.
Take this with you
If it has already happened
- Disconnect the device from the internet immediately, as the advisory instructs, to cut external communications.
- Assume exfiltration has already occurred, including wallet data, even if antivirus reported a clean removal. The advisory is explicit on this point.
- Create a new wallet on a separate device, move all assets across, and store the new seed phrase offline.
- Back up essential data and perform a full operating system reset. Do not clean the machine in place.
- From a different machine, rotate every credential the browser held, every SSH key and platform token on the device, and every cached cloud CLI session.
- Revoke sessions and refresh tokens, not just passwords. A rotated password leaves a live session untouched.
- Tell your employer or your client even though the device was personal, because the advisory's stated follow on is infiltration of the organisation that employs the developer.
- Treat any identity documents that were on the machine as gone, because the advisory's stated follow on is impersonation by North Korean IT workers.
- Report it. In the UK that is Action Fraud, and your bank or exchange if funds moved.
The question that exposes the gap
Put one question to your hiring team this week, and do not accept a reassuring answer.
At what point in our process does a candidate run our code on their own computer?
If the answer is "at the technical stage, we send them a repository", then you have built, entirely in good faith, the exact interaction this advisory describes. Your process and WaterPlum's process are the same process. The only difference is who is on the other end of it, and the candidate has no way to tell.
Then put the harder one to yourself. Right now, somewhere in your engineering organisation, someone is quietly interviewing elsewhere on their own laptop, with your repositories cloned on it and your SSO session live in their browser. Whose control applies to that machine?
Sources
- PrimaryJoint advisory, North Korean WaterPlum, commonly referred to as Contagious Interview, cyber actor group targeting IT professionals. Read in full: source of every scale figure, the infection chain, the malware family descriptions, the mitigations and the indicator strings.Internet Crime Complaint Center (FBI) and partner agenciesaccessed 2026-09-19
- PrimaryOtterCandy, malware used by WaterPlum. Vendor research behind the WaterPlum name, used for the cluster structure, the cross platform scope and the OtterCandy version history.NTT Security Japanaccessed 2026-09-19
- PrimaryOtterCookie, new malware used in Contagious Interview campaign. Used for the naming history and the initial access vectors observed in Japan.NTT Security Japanaccessed 2026-09-19
- PrimaryOFSI advisory on North Korean IT workers. Used for the UK position, which addresses firms that might hire a DPRK IT worker rather than developers who might be targeted.HM Treasury, Office of Financial Sanctions Implementationaccessed 2026-09-19
- PrimaryAlert to countries, companies and other entities regarding North Korean IT workers, the July 2026 alert cited as reference material by the joint advisory.National Police Agency of Japanaccessed 2026-09-19
- Reported byNews report that pointed to the advisory, by Connor Jones, published 18 September 2026.The Registeraccessed 2026-09-19
- Reported byNews report used to cross check the campaign period and the list of issuing agencies.The Recordaccessed 2026-09-19


