// 4 CVE · 2 EXPLOIT IN THE LAST 24H
On September 18, 2026, four intelligence and law-enforcement agencies — Japan's NPA, the FBI, Australia's ACSC, and Germany's BND/BfV — issued a joint advisory revealing an unprecedented picture: the WaterPlum group, also known as Contagious Interview, infected over 30,000 devices across more than 100 countries between December 2025 and July 2026, stealing funds or credentials from over 7,000 cryptocurrency wallets totaling 1.7 billion yen ($10.71 million) transferred to North Korea. The paradigm-shifting finding is that the same actors, using the same infrastructure, operate simultaneously on both sides of the hiring table — as fake recruiters compromising developers, and as fraudulent IT workers using stolen identities to infiltrate Western companies.
{"main_topic":"cybersecurity","topics":["cybersec","phishing","malware","blockchain","crypto"]}

On September 18, 2026, four intelligence and law-enforcement agencies — Japan's NPA, the FBI, Australia's ACSC, and Germany's BND/BfV — issued a joint advisory that assembles an unprecedented picture: the WaterPlum group, also known as Contagious Interview, infected over 30,000 devices in more than 100 countries between December 2025 and July 2026, exfiltrating funds or credentials from over 7,000 cryptocurrency wallets for a total of 1.7 billion yen ($10.71 million) transferred to North Korea. But the finding that upends the traditional advanced persistent threat model is this: the same actors, using the same infrastructure, operate simultaneously on both sides of the table — as fake recruiters who compromise developers, and as fraudulent IT workers who use stolen identities to slip into Western companies.

Key Takeaways
  • The WaterPlum group infected over 30,000 devices in more than 100 countries and stole funds or credentials from over 7,000 cryptocurrency wallets, totaling $10.71 million transferred to North Korea, according to the September 18, 2026 joint advisory.
  • The same IP addresses used by WaterPlum were detected accessing laptop farms, crowdsourcing services, and applying for a job at the exchange bitFlyer, documenting shared infrastructure and personnel with the North Korean IT worker operation.
  • Identities stolen in phishing campaigns are reused by fraudulent IT workers to impersonate victims and obtain paid positions at Western companies.
  • The perpetrators pose as recruiters from startups in AI, blockchain, and NFTs on LinkedIn and job platforms, luring victims into installing malware disguised as video codecs, build commands, or VS Code projects.

How the Ambush Works: The Interview as Infection Vector

WaterPlum has industrialized a security blind spot: the institutional trust surrounding the hiring process. The actors create seemingly legitimate corporate profiles with plausible LinkedIn presences, as observed by Adam Harvey, software developer at the Rust Foundation: These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.

Initial contact comes via credible tech job offers. During video calls, the supposed recruiters use AI-based face-swapping software, then disable the camera after a few seconds citing connection issues. This technique, reported by TechFlowPost, produces visual artifacts that disappear as soon as the video is cut.

The payload arrives in the seemingly routine context of technical preparation. Victims are induced to install fake codecs to join calls, execute build commands that download malicious components, or clone repositories containing compromised Visual Studio Code projects. SecurityWeek confirmed a specific wave targeting Rust developers in June 2026, with a further reference to the compromised arrayref package in August 2026 — though the dossier does not establish with certainty whether these episodes are attributable to WaterPlum or to distinct actors employing the same tactics.

The malware families employed — documented by BleepingComputer — are three: BeaverTail, a JavaScript infostealer distributed via npm packages; InvisibleFerret, a Python backdoor with persistence and data-theft capabilities; and StoatWaffle, a Node.js module that integrates into the VS Code ecosystem. The combination enables both immediate extraction of credentials and crypto assets, and persistent access for follow-on operations.

The Closed Loop: From Victim to Operational Cover

What emerges from the joint advisory is that the campaign does not end with cryptocurrency theft. Identity images stolen during compromises are reused by North Korean IT workers to impersonate victims and generate foreign currency. The handoff is not hypothetical: it is documented in the advisory text cited by BleepingComputer and Cybernews.

StartupFortune reported an emblematic case. In May 2025, the Japanese exchange bitFlyer rejected a candidate suspected of being a North Korean IT worker. The same IP addresses used in that application were also found employed by WaterPlum to access laptop farms and crowdsourcing services. This infrastructural overlap confirms that the two operations — direct theft via fake interview and long-term professional infiltration — share technical and human resources.

The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau, a unit of the regime's Munitions Industry Department. This attribution, present in multiple dossier sources, frames the operation as a component of state strategy, not an initiative of independent criminal groups.

"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets"

Two Fronts, One Battleground for Defenses

WaterPlum's bidirectional structure creates an unprecedented asymmetric security problem in traditional APT models. Developers must defend against a process — the job interview — that until yesterday represented a professional routine. Companies, for their part, must verify that the candidates they hire are not the same individuals who have already compromised their employees, or are not using identities stolen in that same campaign.

The joint advisory cited by Help Net Security is explicit about the extended consequences: Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion. The risk perimeter therefore exceeds the individual developer to touch the corporate networks where they work, the clients of projects they are engaged on, and the software supply chain as a whole.

TechFlowPost reported specific actor activity during Japanese weekends and holidays, when normal verification processes are weakened. The same article references the first takedown of a laptop farm in Japan, though the dossier does not clarify whether this structure was directly managed by WaterPlum or by a parallel IT worker cell.

The Register contextualized the operation within the broader North Korean IT worker ecosystem, estimating roughly 100,000 units employed or seeking work worldwide and roughly $500 million per year in revenue generated for the regime. These figures refer to the broader scheme, not specifically to WaterPlum, and should be read as an indication of scale rather than a direct measure of the campaign under examination.

What to Do Now

The joint advisory and technical sources converge on several priority actions, without however providing an exhaustive checklist. Documented recommendations include:

  • Control the terms of first contact. The Rust project team framed the principle in stark terms: The single most effective defense is controlling the terms of first contact. This means independently verifying the existence of the company offering the interview, not using links provided by the supposed recruiter to access sites or repositories, and moving communication to authenticated channels.
  • Isolate the test environment during technical interviews. Execute build commands, clone repositories, or install dependencies in a virtual machine or container without access to credentials, wallets, or sensitive data. None of the dossier sources suggest using production environments for selection activities.
  • Verify candidate identity with non-delegable methods. The bitFlyer case shows that the same IP addresses can link a compromise operation to a job application. Linked sources report the use of PiKVM and anomalous hardware in North Korean IT workers detected by Huntress, though these data refer to infiltration vectors different from the fake interview.
  • Reevaluate screening policies for previously compromised identities. The advisory documents the systematic reuse of stolen identities. Companies that manage candidate data should consider whether current checks detect this specific recurrence.

Why This Changes the Threat Paradigm

The lesson of the WaterPlum dossier is not in the volume of compromised devices or the value of stolen funds, significant as they are. It lies in the transformation of an entire phase of the economic cycle — the meeting of labor supply and demand — into a shared attack surface between two profit models. Traditional APTs exfiltrate data for intelligence or sabotage infrastructure for strategic effect. WaterPlum instead monetizes the very moment of professional trust, and does so in both directions: stealing from the developer seeking work, and using what was stolen to get its own operative hired by that same company.

The hiring process, with its established technical rituals — the video call, the coding test, the environment setup — can no longer be considered security-neutral. The source does not quantify the revenue derived from fraudulent employment versus direct cryptocurrency theft, nor does it delineate the exact perimeter of non-financial data exfiltrated. What remains documented is that the mechanism is active, shared, and directed by a government structure.

For Western organizations, this means that due diligence on candidates and the security of their own technical staff are no longer separate compartments. Who gets compromised today can become the identity cover for who gets hired tomorrow.

FAQ

Are WaterPlum and Contagious Interview the same group?

Yes. WaterPlum is the name attributed by authorities to the group previously known in the security community as Contagious Interview or DeceptiveDevelopment, active at least since 2023 according to linked sources.

Why were Rust developers targeted?

SecurityWeek documented a specific wave in June 2026. The targeting likely exploits the active technical community and the central role of maintainers of popular crates, though the dossier does not specify the actor's selection criteria.

What happens to companies that unknowingly hire North Korean IT workers?

Linked sources report sanctions and legal exposure: in 2026, two U.S. laptop farm cases produced convictions with $1.2 million in seizures and involvement of 70 companies, though these figures refer to operations distinct from WaterPlum and provide legal context rather than a direct measure of risk.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. securityweek.com
  3. bleepingcomputer.com
  4. theregister.com
  5. darkreading.com
  6. techflowpost.com
  7. startupfortune.com
  8. cybernews.com