North Korea's Fake Job Interviews Dr $11 Million From 7,000 Crypto Wallets, Agencies Say
Key Takeaways
- •Seven agencies from Japan, the United States, Australia and Germany issued the joint advisory on September 18.
- •The WaterPlum group, known in the security industry as Contagious Interview, took funds or credentials from more than 7,000 cryptocurrency wallets and moved roughly $10.71 million to North Korea.
- •At least 30,000 devices across more than 100 countries were infected between roughly December 2025 and July 2026, targeting web designers, engineers and crypto, blockchain and Web3 specialists.
- •The group impersonated AI, crypto or NFT companies to lure developers into fake interviews and delivered five malware families, including BeaverTail, InvisibleFerret and StoatWaffle.
- •Japanese authorities dismantled the nation's first laptop farm run by a domestic enabler, finding evidence that several hundred million yen in cryptocurrency had moved abroad.

Seven law enforcement and intelligence agencies across four countries — Japan, the United States, Australia and Germany — said that a North Korean cyber group posing as recruiters has taken funds or credentials from more than 7,000 cryptocurrency wallets and moved roughly $10.71 million — about ¥1.7 billion — to North Korea, according to a joint advisory published on September 18.
The operation targeted IT professionals in Japan, the U.S., Europe and beyond, compromising job seekers' computer networks, harvesting sensitive data and stealing cryptocurrency.
The group, which Japan's National Police Agency calls WaterPlum and which the security industry knows as Contagious Interview, infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026. Targets included web designers, engineers and specialists in crypto, blockchain and Web3 work. For developers and designers in those fields, a routine coding test or interview assignment sits squarely inside a documented attack chain.
North Korean cyber group "WaterPlum" is compromising job seekers' computer networks, harvesting sensitive data, and stealing cryptocurrency - targeting IT professionals in Japan, U.S., Europe, and beyond. Read our advisory with @FBI and @NPA_KOHO at pic.twitter.com/Q74qeXWQoP
— DoD Cyber Crime Center (DC3) (@DC3Forensics) September 18, 2026
The advisory is signed by Japan's National Police Agency and National Cybersecurity Office, the FBI and the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND foreign intelligence service and BfV domestic security agency. Joint publication of this kind puts the same set of indicators in front of defenders in all four countries at once.
The NPA and the FBI assess that both WaterPlum and some of North Korea's remote IT workers report to the 313 General Bureau of the Munitions Industry Department, which sits under the Workers' Party central committee. The two operations also used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs — evidence the agencies treat as confirmation that the two are one operation.
How the job-interview scheme works
The actors impersonate AI, crypto or NFT companies and approach developers through social media, job boards and freelance marketplaces before setting a technical interview or coding task. Candidates are then told to download files from developer platforms, either to finish the assignment or to fix an apparent fault in the video call. The packages are used to harvest sensitive data and steal cryptocurrency from infected machines. The advisory names five malware families carried in those packages, among them BeaverTail, InvisibleFerret and StoatWaffle, the last of which hides in blockchain-themed repositories. The industries named as targets map directly onto the assets at risk, since a single infected machine can surrender both its data and any cryptocurrency it holds.
Investigators also logged what they observed of the crew itself. Members used AI face-swapping software in interviews before cutting their video and asking the candidate to do the same, blaming the connection. They practiced Japanese pronunciation with text-to-speech tools, worked consistently on free tiers of machine-translation and AI services, and on holidays celebrated in North Korea played games and watched soccer videos instead of running their usual operations.
First laptop farm dismantled in Japan
Japanese authorities also identified and dismantled a laptop farm run by a domestic enabler — the first such case in the country — finding evidence that several hundred million yen in crypto had moved abroad. A laptop farm is typically an enabler's home, where work computers are run remotely by IT workers in North Korea, China or Russia.
The advisory also documents warning signs for employers. A Japanese crypto exchange turned away an applicant in May 2025 whose résumé claimed implausibly broad skills and whose English did not match the record. Other tells include refusing to meet in person, asking to be paid in crypto, and glancing repeatedly at a second screen. With the NPA and FBI assessing that WaterPlum and the remote IT worker program share a command structure, those screening cues run in both directions — for candidates weighing an unsolicited approach and for employers vetting remote hires.
Part of a far larger campaign
The theft sits inside a much broader pattern of North Korean cyber operations. CertiK attributed 60% of all crypto theft losses in 2025 — some $2.06 billion — to North Korea-linked groups, and April's $285 million Drift Protocol hack followed six months of attackers posing as a quantitative trading firm. With documented activity running through July 2026, the advisory's concrete artifacts — the five named malware families, the fake-recruiter approach and the laptop-farm configuration — give organizations a defined set of markers for reviewing their own hiring records and endpoints.