CYOPS · Cyber Operations

North Korea’s fake recruiters and fake applicants log in from the same addresses, and most defenders split them across two departments

A seven-agency advisory published on 18 September attributes 30,000 infected developer machines and ¥1.7 billion in stolen cryptocurrency to WaterPlum, and ties the group to North Korea's IT-worker scheme through shared IP addresses. The inbound fake interview and the outbound fake hire are one operation, and the developer's own laptop sits between them.

The finding

On 18 September 2026 the National Police Agency of Japan (NPA), Japan's National Cybersecurity Office, the FBI, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND and BfV published a joint advisory on the North Korean group WaterPlum, which industry tracks as Contagious Interview [1][2][3]. From around December 2025 through July 2026 the group compromised at least 30,000 PCs in more than 100 countries, including Japan and the United States. It took funds or account credentials from over 7,000 cryptocurrency wallets and moved at least ¥1.7 billion, which the agencies equate to US$10.71 million, to the DPRK [1].

Those are the headline numbers, and they describe individual developers losing money. The analytically important material is further down. The NPA and the FBI assess that WaterPlum actors and some North Korean IT workers operate under the same organisation, the 313 General Bureau of the Munitions Industry Department, subordinate to the Workers' Party Central Committee [1]. Section 5 of the advisory supplies the evidence: WaterPlum actors and North Korean IT workers used the same IP addresses to reach laptop farms, to use crowdsourcing services and to apply for a job at a Japanese cryptocurrency exchange [1].

“Some WaterPlum actors also operate as North Korean IT workers”

Joint advisory, NPA, NCO, FBI, DC3, ASD's ACSC, BND and BfV, 18 September 2026 [1]

The fake recruiter who compromises a developer and the fake applicant who gets hired by a company are therefore not two threats that happen to come from the same country. According to the agencies they belong to one organisation, work from shared infrastructure, and are sometimes the same people.

Inbound: the interview that installs a backdoor

WaterPlum reaches its targets through social media, online job platforms, gig work platforms and freelance marketplaces. Its operators impersonate AI, cryptocurrency and NFT companies, and sometimes recruiting services [1]. The target is asked to take a technical interview or complete a coding assignment. During it, they are told to download and run files from developer collaboration platforms and code repositories, either to complete the task or to fix a supposed error in the video conferencing tool [1]. The payloads arrive in malicious npm packages carrying BeaverTail, InvisibleFerret, OtterCookie, OtterCandy or StoatWaffle, and are followed by remote access trojans and infostealers [1]. What the actors collect is broader than wallets: browser-stored credentials, keystrokes, clipboard contents, screenshots, seed phrases and scanned identity documents such as driving licences and passports [1].

StoatWaffle shows how little the attack needs. NTT Security documented that from around December 2025 the operators shipped repositories disguised as blockchain projects, containing a .vscode/tasks.json file set to run on folder open, so that the payload runs as soon as a developer opens and trusts the folder in VS Code; the downloader pulls its next stage from a web application hosted on Vercel [7]. Microsoft changed the default of the task.allowAutomaticTasks setting to off in VS Code 1.109, released in early February 2026 [9], and The Hacker News reports that version 1.110 added a further warning when automatic tasks are detected [8]. The advisory nonetheless still instructs developers to answer “No” to the prompt asking whether they trust the author of the files, and not to open unknown projects from a folder they have previously marked as trusted [1]. The remaining control is a dialogue box, answered by the target, during a job interview, while a supposed hiring manager waits.

The advisory's notes on operator behaviour are unusually concrete. Operators ran interviews through AI face-swapping software, then switched video off after a few minutes and asked the target to do the same, citing network problems. They practised Japanese pronunciation with text-to-speech tools, consistently used free machine translation and AI service plans, and stopped work on North Korean public holidays to play games and watch football [1]. The Register's reporting of the same advisory lists that video pattern, face-swap artefacts followed by a camera switched off soon after the call begins, among the red flags for interviewers [6].

Outbound: the applicant who is not who they claim

The other half of the operation earns wages. The advisory describes laptop farms, usually at an enabler's home, where employer-issued computers are set up for remote control, together with virtual private servers that enablers rent to hide where the work is really done [1]. The IT workers are usually in North Korea, China or Russia, with a small number in Africa and Southeast Asia. They use identity images and bank accounts supplied by enablers to win contracts and collect payment [1]. Japanese authorities identified, investigated and dismantled a laptop farm in Japan for the first time, and found evidence that several hundred million yen had been transferred abroad [1][5]. The advisory warns that paying such workers may breach domestic law and sanctions against the DPRK [1].

Revenue is the main purpose, but not the only one. The advisory records one IT worker who extorted a company over payment and published its source code, and another, hired for website maintenance, who defaced the client's site and took it offline [1]. The FBI had described the extortion pattern in January 2025, along with the use of AI and face-swapping in video interviews [13].

The one case the agencies set out in detail is regionally specific. In May 2025 a Japanese cryptocurrency exchange received a forged CV through its recruitment form, submitted over a VPN [1]. The applicant listed more than ten skills in each of several categories, claimed a European degree followed by jobs in quick succession across Europe and Asia, and on camera said he was born in Malaysia, lived in Finland, and spoke Malay and Chinese as native languages [1]. His English did not match the career he claimed, and he could not discuss most of the skills listed. The exchange did not hire him [1]. The advisory thanks bitFlyer and NTT Security for their cooperation [1].

One adversary, two departments

The advisory itself describes how the two halves feed each other. A developer compromised in a fake interview loses identity documents and credentials. The agencies say stolen IDs “can be used by North Korean IT workers to impersonate victims” to earn foreign currency, and that stolen credentials can be used against the victim's employers, clients and contractors [1]. The inbound attack supplies the identities and access that the outbound scheme then uses. The shared IP addresses in section 5 show that the two run on the same infrastructure [1].

Most organisations do not defend it that way. Candidate fraud is handled by recruiting, sometimes with an identity verification vendor. A job seeker's personal laptop belongs to nobody's security programme, and a freelancer's belongs to nobody's at all. Endpoint detection covers only corporate devices. Yet the advisory is addressed explicitly to “businesses that outsource or commission work via crowdsourcing” as well as to IT professionals [1]. The freelancer's own machine, outside every client's controls, is where client credentials, repositories and payment details are kept. Help Net Security described the scheme as running both ways [15]. The advisory goes further and says the two directions share addresses [1].

Two cautions apply to the numbers. The 30,000 figure counts PCs and is not broken down by country or by whether the device was personal or corporate, so it measures reach, not how many organisations were entered [1]. And the malware list varies by source: the advisory names five families [1], while The Hacker News lists nine, adding FlexibleFerret, GolangGhost, PylangGhost and RATatouille, along with ten vendor names for the same actor [4]. Detection built on one list will miss parts of the other.

The supply chain extension

On 17 September, the day before the advisory, the Rust Project warned its community about targeted attacks on prominent contributors [10]. The pattern it describes is the same: a video call set up for a job, a project or a contract, during which the target is persuaded to install something such as a supposedly missing audio codec or to run a command. It is supported by new but plausible company profiles with LinkedIn presences [10][12]. The post describes the method as known to be used by the DPRK. It links the warning to a June wave against Rust developers and to the August compromise of the arrayref crate, but says it is not clear whether these are one campaign [10].

The arrayref incident shows what is at stake. On 20 August a malicious arrayref 0.3.10 was published to crates.io, pulling in a proc-macro1 crate whose build script downloaded a payload. It was online from 07:15 to 08:41 UTC, and the project believed the author's computer or credentials had been compromised, not that the author had acted maliciously [11]. The Register puts arrayref's lifetime downloads at 245 million [12]. Against a maintainer, the fake interview is not a theft of one person's wallet. It is a way into every build that depends on their package.

Regional reading

The Malaysian persona in the exchange case suggests the operators treat Malaysian nationality as plausible cover for a remote, English-language technical hire [1]. The advisory also places some of the IT workers physically in Southeast Asia [1]. Neither point says Malaysians were victims: the advisory gives no Malaysian figures, and its 100-country total is not itemised [1]. But Malaysian companies that commission web, blockchain and application work through freelance platforms are exactly the businesses the advisory addresses. The region's developers are recruited through the same marketplaces WaterPlum uses [1]. Japan's own July 2026 alert on North Korean IT workers, issued by five Japanese ministries and agencies, was framed as coordination with the United States and South Korea [14]. This advisory adds Australia and Germany, but no Southeast Asian co-signatory.

What defenders should do

  • Put candidate fraud and developer targeting in one threat model. Share indicators such as IP addresses, email domains and fake company profiles between recruiting, security and procurement, since the advisory's own evidence is shared infrastructure [1].
  • Enforce task.allowAutomaticTasks as off through managed VS Code settings, keep Restricted Mode as the default for anything downloaded, and never unpack external projects under a folder already marked as trusted [1][9].
  • If you run technical interviews, provide a hosted or disposable environment. Tell staff and contractors that a legitimate employer will not ask them to run code on their own machine, and that any request to do so should end the process [1].
  • Treat commands containing curl, base64, -enc, mshta or Invoke-WebRequest in an interview or assignment as hostile unless fully understood [1].
  • After a suspected infection, disconnect the device and assume data has already left. Move cryptocurrency to a new wallet created on a separate device, rebuild the operating system, and rotate every employer and client credential that was held on the machine [1].
  • In hiring, check that IP addresses match the claimed residence, call the phone numbers given, probe each skill on the CV, ask ordinary personal questions, and refuse payment in cryptocurrency or to accounts in another name [1][13].
  • In outsourcing, write flow-down clauses that cover subcontractors, grant the minimum access to source code and credentials, and revoke accounts and sessions promptly when doubts arise [1].
  • Maintainers of widely used packages should initiate calls themselves on trusted platforms, confirm MFA on registry accounts and review login activity after any unsolicited approach [10].

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: the joint advisory text was read from the version published by the Australian Signals Directorate; the FBI-hosted PDF and the National Police Agency's Japanese PDF of the same document could not be text-extracted by this desk and are cited as copies of that document, not as independently checked texts. The infection figure is a count of PCs and the advisory does not break it down by country or by personal versus corporate devices. The malware family list differs between the advisory and secondary reporting, and both are given. The detail that VS Code 1.110 added a further warning is carried from The Hacker News and attributed to it. The Rust Project does not state that its incidents are part of the WaterPlum campaign, and nothing here should be read as saying they are. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.