Summary
- Japanese, US, Australian, and German authorities attribute WaterPlum, also known as Contagious Interview, to North Korean cyber operations.
- Authorities say at least 30,000 devices were compromised and credentials or funds were taken from more than 7,000 cryptocurrency wallets.
- The advisory also documents North Korean IT-worker activity in Europe, extending the risk beyond malicious recruitment into contractors, identity, and corporate access.
Japanese, US, Australian, and German authorities have attributed a large-scale malicious recruitment campaign to North Korean cyber operators, saying the activity compromised at least 30,000 devices across more than 100 countries and exposed funds or credentials associated with more than 7,000 cryptocurrency wallets.
The joint advisory, led by Japan’s National Police Agency and National Cybersecurity Office alongside the FBI, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate, Germany’s BND intelligence service, and Germany’s BfV domestic intelligence agency, names the group WaterPlum. The operation is more widely tracked as Contagious Interview.
The agencies assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which sits under the Workers’ Party of Korea. That attribution is the assessment of the participating governments rather than an independently established finding.
According to the advisory, WaterPlum operators pose as prospective employers and approach software developers and other technology professionals with apparently legitimate job opportunities. Targets can then be directed to complete coding assignments or troubleshoot software during an interview, creating an opportunity to persuade them to execute malicious files.
The agencies said the operation has used malicious npm packages containing malware including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Once a system is compromised, the operators can harvest browser authentication data, cryptocurrency wallet material, clipboard contents, keystrokes, screenshots, identity documents, and other files.
Investigators said activity observed between around December 2025 and July 2026 affected at least 30,000 computers. They attributed the transfer of 1.7 billion Japanese yen, equivalent to about $10.7 million, in cryptocurrency assets to North Korea. Credentials or funds connected with more than 7,000 wallets were affected, according to the advisory.
The corporate exposure extends beyond the individual developer initially approached. The agencies warn that credentials taken from a contractor or employee can create routes into employers and clients, while stolen identity documents can be reused by North Korean IT workers seeking paid technology work under false identities.
The same advisory documents IT-worker operations involving Japan, the United States, and Europe. These workers can use laptop farms and remote infrastructure to make their location appear consistent with the identity they claim, allowing them to obtain contracts and corporate access while physically operating elsewhere.
That combination makes recruitment, contractor management, developer security, and sanctions exposure part of the same problem. A technically legitimate worker account can create significant access if the identity behind it is false, while a malicious recruitment approach can compromise an otherwise legitimate developer before the attacker ever targets the developer’s employer directly.
The authorities also described cases in which North Korean IT workers went beyond revenue generation. In one, an IT worker allegedly extorted a company and published proprietary source code; in another, a worker hired for website maintenance allegedly defaced the customer’s website and made it unavailable.
The European element is therefore not limited to machines infected by recruitment malware. The advisory explicitly places North Korean IT-worker activity in Europe and describes work histories and identities designed to appear connected with European countries. Companies using remote developers, freelance marketplaces, outsourcing chains, or subcontractors can inherit both identity and access risk from parties several steps removed from their own hiring process.
The disclosure brings together two previously adjacent North Korean cyber problems — malicious recruitment and covert IT employment — as overlapping routes to money, credentials, intellectual property, and corporate systems. The agencies’ figures also put a scale behind activity that has often been documented through individual campaigns and malware discoveries rather than consolidated victim numbers.





