BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Interviewers and job applicants are both fake? Japan's National Police Agency, the FBI, and other multinational agencies expose North Korean hackers' "recruitment bureau"

Asher
Odaily资深作者
@Asher_0210
This article is about 2872 words, reading the full article takes about 5 minutes
The hacker group WaterPlum and some IT personnel are all affiliated with the 313th General Bureau of North Korea's Military Industry Department.
AI Summary
Expand
  • Core viewpoint: The North Korean hacker group WaterPlum (Contagious Interview) impersonates recruiters to trick developers into running malicious code, having already infected at least 30,000 devices worldwide and stolen over 7,000 crypto wallets, involving assets of at least $10.71 million, with attack targets expanding down to individual developers and Web3 practitioners.
  • Key elements:
    1. The attacks use fake job postings as an entry point, planting malicious NPM packages through coding tests and code repositories, involving multiple malware families such as BeaverTail and InvisibleFerret.
    2. From December 2025 to July 2026, the attacks affected more than 100 countries, stealing wallet private keys, seed phrases, browser credentials, identity documents, and other sensitive data.
    3. The stolen identity documents are used by North Korean IT personnel to impersonate overseas developers when applying for jobs. Japan has for the first time uncovered such a "remote work base" within its territory, involving the transfer of hundreds of millions of yen.
    4. Crypto companies are key infiltration targets. Suspected North Korean IT personnel have applied to Japanese exchanges using forged resumes, displaying characteristics during interviews such as mismatched English proficiency and frequently glancing at a secondary screen.
    5. Multinational agencies recommend: do not run unfamiliar code on devices that hold crypto assets. After infection, assume the wallet has been compromised and create a new wallet on a new device while resetting the system.

Original source: npa.go.jp

Compiled by Odaily (@OdailyChina); translated by Asher (@Asher_ 0210)

On September 18, Japan's National Police Agency, the US Federal Bureau of Investigation, and other multinational agencies jointly disclosed that the North Korean hacking group WaterPlum (also known as "Contagious Interview") has long been impersonating recruiters or crypto companies, luring developers into running malicious code under the guise of coding tests and project collaboration.

Between December 2025 and July 2026, the group infected at least 30,000 devices across more than 100 countries, moving funds out of or stealing account credentials from over 7,000 crypto wallets, involving at least $10.71 million in crypto assets.

Unlike past attacks that primarily targeted trading platforms and large institutions, WaterPlum has pushed its targets further down to individual developers, freelancers, and Web3 practitioners. Attackers not only directly steal wallet assets, but also use compromised computers and identity information to infiltrate the victims' employers, creating conditions for subsequently stealing trade secrets, carrying out extortion, and even impersonating victims to apply for jobs.

The Attack Begins with a "High-Paying Job Offer"

WaterPlum's most common attack vector is not a phishing email, but a seemingly normal job opportunity.Attackers impersonate AI, crypto, or NFT companies and contact software developers through social media, online recruitment platforms, gig platforms, and freelancer marketplaces. After establishing initial communication, they typically arrange an online video interview or ask the applicant to complete a coding test.

The actual attack occurs during the "technical assessment." Attackers may send the applicant a code repository and ask them to run the project locally, fix bugs, or troubleshoot why video conferencing software isn't working properly. On the surface, these projects are ordinary JavaScript, Python, or VS Code projects, but malicious code has already been embedded inside.

WaterPlum frequently uses NPM packages implanted with malicious programs(Node.js package manager), involving multiple malware families such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Some of these malicious projects exploit the .vscode/tasks.json configuration file to automatically execute code once the user opens and trusts the VS Code folder. For the victim, the entire process may simply involve downloading the code, opening the project, and running the program as the "interviewer" requests — yet the malware has already been installed in the background.

After gaining initial access, the attackers deploy remote access trojans to maintain long-term control over the device and use information stealers to collect data. The main targets include:

  • Accounts and passwords saved in browsers;
  • Clipboard contents, keystroke logs, and screenshots;
  • Crypto wallet private keys, seed phrases, and related data;
  • Files on the computer and in shared folders;
  • Images of identity documents such as driver's licenses and passports.

This information is ultimately sent to servers controlled by the attackers. Even if the victim's wallet holds no assets at the time, as long as the private key or seed phrase has been leaked, the attackers can continue to monitor the address over the long term and transfer funds once they arrive.

Once a device is compromised, the risk is not limited to personal wallets.Developers typically have access to company code repositories, cloud services, and internal systems. WaterPlum may use login credentials and existing permissions stored on the device to enter employer, client, or partner systems, continue stealing trade secrets, move laterally within corporate networks, and even use sensitive data for extortion.

"Remote Work Bases" Hidden in Overseas Residences

The driver's licenses, passports, and other identity documents stolen by WaterPlum serve another purpose: they are handed to North Korean IT workers to impersonate the victims, seek jobs overseas, and earn foreign currency. WaterPlum primarily delivers malware through fake job postings, while North Korean IT workers disguise themselves as overseas developers to enter companies — the two overlap in personnel and infrastructure. Japan's National Police Agency and the FBI assess that WaterPlum members and some North Korean IT workers both belong to Bureau 313 of the Munitions Industry Department under the Central Committee of the Workers' Party of Korea.

To bypass corporate verification of employee identity and work location, North Korean IT workers collaborate with overseas intermediaries, who place work computers in local residences, provide identity information, and collect salaries on their behalf. The actual work is performed remotely by personnel located in North Korea, Russia, and elsewhere — essentially remote work bases that help the real operators disguise their location and identity.

Through this model, North Korean IT workers can use local computers and networks in Japan or the US to log into corporate systems, making companies believe the employee is locally based. The intermediaries also receive company-issued computers, provide identity documents and bank accounts, and then forward the received salaries to the actual workers.

Japanese authorities have for the first time uncovered such a base operating within Japan. The investigation found that the individuals involved not only helped North Korean IT workers disguise their identities and take on work, but also transferred funds worth hundreds of millions of yen abroad, including crypto assets.The notice warns that companies or individuals who provide work to North Korean IT workers, pay them, or help them obtain identity information, bank accounts, and remote equipment may violate local laws and breach sanctions against North Korea.

The risks posed by these individuals once they enter a company go beyond salaries flowing to North Korea. One North Korean IT worker extorted an employer over a pay dispute and publicly released the company's proprietary source code; another, hired to maintain a website, maliciously tampered with the company's website, rendering it inaccessible.

Faked Resumes, Applying to Japanese Crypto Exchanges

Crypto companies are one of the key industries North Korean IT workers seek to enter.

In May 2025, a Japanese crypto exchange received an application for an engineer position. The applicant was suspected to be a North Korean IT worker who accessed the recruitment page via VPN and submitted a forged resume. The resume appeared remarkably "versatile": the applicant claimed mastery of a large number of programming languages, blockchain technologies, crypto technologies, and cloud services, listing more than 10 relevant areas of knowledge and experience in each category. Their personal history included a European university education and experience working in multiple cities across Europe and Asia within a short period. In the video interview, the applicant claimed to be born in Malaysia, living in Finland, with native languages of Malay and Chinese. However, their English proficiency was clearly inconsistent with the claimed education and professional background — they could only answer simple questions and could not explain most of the technical skills listed on their resume in detail.

The notice also summarized other common traits of suspected North Korean IT workers during interviews, including refusing to meet in person, requesting payment in crypto, frequently looking at another screen, occasionally hearing other people's voices in the background, and repeated video or audio lag. Frequently checking another screen may indicate the applicant is reading answers provided by someone else; even if only one applicant appears on screen, multiple people may be collaborating behind the scenes to collectively piece together the technical skills listed on the resume.

After Discovering an Infection, Simply Removing Malware Is Not Enough

Once unknown code has been run on a computer, you cannot conclude that the device and wallet are still safe simply because wallet assets have not yet been transferred out. The malware may have already obtained private keys, seed phrases, or browser login credentials without using them immediately. The attackers may also maintain a backdoor on the device, waiting for a more opportune moment to transfer funds.

Multinational agencies recommend not running code provided by strangers directly on devices that store crypto assets or handle sensitive data.If testing is truly necessary, use a sandbox or virtual machine isolated from your daily environment, and check before running whether the project contains obfuscated, unreadable code or code that automatically downloads other files.

Scripts containing download, encoding, or hidden execution commands such as curl, base64, mshta, and Invoke-WebRequest should also be treated with extra caution — do not run them without understanding their specific purpose. If antivirus software has already flagged an infection on the device, or if you have previously run programs provided by a suspicious recruiter, immediately disconnect from the network. Even if the malware is subsequently removed, you must assume that wallet data has been leaked, create an entirely new wallet on another secure device, transfer all assets, and store the new seed phrase offline.

Because undetected backdoors may still remain on the infected computer, the safest approach is to back up necessary data and then completely reinstall or reset the operating system, rather than continuing to use the original environment.

Safety
Welcome to Join Odaily Official Community