A sweeping international joint advisory issued by intelligence, defense, and law enforcement agencies from Japan, the United States, Australia, and Germany has revealed the true scale of a sprawling cyber-espionage and financial theft operation orchestrated by North Korea’s notorious WaterPlum hacker collective, widely known across the cybersecurity industry as Contagious Interview. According to the comprehensive investigative findings, this state-sponsored threat group successfully infected at least 30,000 distinct computing devices spread across more than 100 countries between December 2025 and July 2026. During this extended campaign, the malicious actors systematically compromised over 7,000 cryptocurrency wallets, stripping victims of sensitive login credentials, private cryptographic keys, and substantial digital asset funds.
Financial tracking embedded within the international advisory indicates that at least JPY 1.7 billion, equivalent to roughly $10.7 million USD, was directly transferred to accounts under North Korean control during the seven-month operational window. However, intelligence analysts emphasize that this figure accounts strictly for verified direct cryptocurrency thefts and does not fully capture the broader economic damage inflicted upon corporate networks, intellectual property repositories, and compromised businesses worldwide.
The joint advisory—released collaboratively by Japan’s National Police Agency (NPA) and National Cybersecurity Office, the United States Federal Bureau of Investigation (FBI), the Department of Defense’s Cyber Crime Center (DC3), the Australian Cyber Security Centre (ACSC), and Germany’s Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV)—places the WaterPlum group squarely within the operational architecture of the regime’s military-industrial complex. Specifically, both the NPA and the FBI have assessed with high confidence that WaterPlum operatives, alongside various clandestine North Korean IT workers deployed globally, take direct orders from the 313 General Bureau. This specialized entity operates under the Munitions Industry Department, which itself remains directly subordinate to the powerful Central Committee of the Workers’ Party of Korea.
Detailed Chronology and Operational Timeline
The origins of the WaterPlum syndicate and its intertwined IT worker methodologies trace back several years, evolving from rudimentary freelance credential farming into a highly sophisticated, multi-vector cyber-attack infrastructure. However, the precise operational phase detailed in the recent intelligence dossier concentrates on a hyper-active period spanning from December 2025 through July 2026.
During December 2025, security researchers and international intelligence services began observing an aggressive uptick in fraudulent job applications targeting Western and Asian technology hubs. By early 2026, the campaign had matured into a well-oiled machine utilizing advanced social engineering, customized malware variants, and global proxy infrastructure. Throughout the spring of 2026, thousands of web designers, software developers, and Web3 specialists fell victim to technical interview traps, unknowingly seeding malicious code into commercial repositories.
By July 2026, the accumulation of forensic evidence allowed the multi-nation coalition to map out the complete network infrastructure, culminating in the historic dismantling of a physical laptop farm operating within Japan—a critical milestone in counter-cyber operations against Pyongyang’s revenue-generation apparatus.
Sophisticated Social Engineering: Fake Interviews and Poisoned Code Repositories
The primary vector employed by WaterPlum to breach secure corporate networks and individual developer machines relied heavily on targeted social engineering under the guise of legitimate employment opportunities. The threat actors routinely posed as recruiters, human resources personnel, or engineering managers representing fictional or hijacked entities ostensibly operating within the artificial intelligence, decentralized finance, cryptocurrency, and non-fungible token (NFT) sectors.
Targeting high-value technical personnel—including software engineers, front-end and back-end web developers, blockchain architects, and systems administrators—the hackers advertised lucrative remote positions across popular social media platforms, professional networking sites, niche job boards, and global freelance marketplaces. Once a prospective victim expressed interest, the recruitment process swiftly moved to technical interviews and practical coding assignments.
Under the pretext of evaluating the candidate’s coding proficiency, the fraudulent employers instructed applicants to download, configure, and execute project files hosted on prominent developer platforms and decentralized code repositories. Hidden within these seemingly innocuous project directories were malicious Node Package Manager (NPM) packages carrying payloads of advanced information-stealing malware and remote access trojans (RATs), including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Of particular concern to security analysts is the StoatWaffle malware variant, which is strategically concealed inside blockchain-themed Visual Studio Code (VSC) projects. StoatWaffle is engineered to execute malicious code automatically the moment an unsuspecting victim opens and grants trust to the project folder. Cybersecurity authorities have strongly advised developers to adopt defensive habits, such as opening unknown or unverified software projects strictly in Visual Studio Code’s "Restricted Mode" and meticulously auditing any associated "tasks.json" configuration files prior to execution.
Once successfully established within a victim’s local machine, the malware initiates a comprehensive reconnaissance and data-exfiltration protocol. Threat actors deploy sophisticated infostealers to harvest stored browser credentials, active session tokens, keystrokes, real-time screenshots, cryptographic wallet private keys, seed phrases, and personal identification documents. Crucially, these infected workstations often served as an initial beachhead, granting the attackers lateral movement into the corporate networks and proprietary source code repositories of the victims’ actual employers.
The Convergence of WaterPlum and State-Sponsored IT Workers
A significant revelation within the joint intelligence advisory is the confirmed operational overlap between the WaterPlum hacking collective and North Korea’s state-managed overseas IT worker scheme. Investigators established that individual operatives frequently cross boundaries, participating simultaneously in cyber-extortion, malware distribution, and disguised freelance software development aimed at generating foreign currency for the North Korean regime.
The convergence was substantiated by digital forensics showing that WaterPlum operatives and North Korean IT workers utilized identical Internet Protocol (IP) address spaces to access remote laptop farms, commercial crowdsourcing platforms, and enterprise networks. In one specific instance highlighted by investigators, the exact same infrastructure was used to apply for legitimate-seeming software engineering roles at a major Japanese cryptocurrency exchange.
To maintain the illusion of legitimacy, these overseas workers rely extensively on domestic accomplices—often referred to as "enablers"—who operate unauthorized "laptop farms." These farms are typically established within residential properties in Western and allied nations, where employment-authorized computers are left permanently powered on, connected to corporate networks, and remotely controlled by North Korean handlers via Virtual Private Servers (VPS). Enablers play a vital role in the supply chain of fraud by providing stolen or fabricated identity documents, setting up localized bank accounts, and renting residential proxy networks to mask the true geographic origin of the operators.
Significantly, the investigative push yielded tangible law enforcement victories. Japanese authorities successfully identified, raided, and dismantled a domestic laptop farm utilized by North Korean operatives—marking the first time Japanese law enforcement has physically neutralized such an asset on home soil. Financial investigations conducted concurrently by Japanese and international agencies suggest that North Korean IT workers operating through these domestic channels successfully laundered and moved several hundred million yen abroad, utilizing a combination of traditional fiat banking channels and obscured cryptocurrency transactions.
While many of these covert workers focus on stealthy long-term employment to siphon wages back to Pyongyang, others resort to overtly malicious tactics when disputes arise or when opportunities for direct financial extortion present themselves. The advisory documented several instances where North Korean IT workers turned destructive after securing employment: in one case, a worker extorted a corporate client over a payment dispute and publicly leaked proprietary source code; in another, an operative deliberately defaced a client’s public-facing website, taking critical business infrastructure offline until ransom demands or wage disputes were addressed.
Official Responses and Strategic Implications
The publication of this coordinated international advisory underscores a profound shift in how allied nations approach state-sponsored cyber criminality. Rather than treating North Korean cyber attacks merely as isolated financial crimes or intellectual property thefts, governments are increasingly classifying them as national security threats that directly undermine the stability of the global digital economy and the integrity of international financial markets.
In response to the escalating threat posed by WaterPlum and associated IT worker networks, cybersecurity agencies have outlined a series of rigorous mitigation strategies for organizations across all sectors, particularly those engaged in technology, finance, and Web3 development. Corporations and small-to-medium enterprises are strongly urged to overhaul their onboarding and contractor verification processes. Recommendations include conducting rigorous, multi-factor identity verification for all remote applicants—such as live video interviews with mandatory visual confirmations—and scrutinizing the credentials of downstream subcontractors who may introduce unvetted personnel into a corporate supply chain.
Furthermore, organizations are advised to strictly enforce the principle of least privilege regarding remote contractors and external developers. This includes isolating contractor environments from core intellectual property, restricting direct access to production source codes and master cryptographic credentials, and implementing robust endpoint detection and response (EDR) solutions capable of identifying anomalous execution behaviors typical of infostealers like BeaverTail and StoatWaffle.
As geopolitical tensions persist and state-backed threat actors continue to refine their exploitation of remote work cultures and decentralized development ecosystems, the international cyber intelligence community remains on high alert. The dismantling of the Japanese laptop farm and the public exposure of the 313 General Bureau’s operational wings represent critical steps in disrupting Pyongyang’s illicit revenue streams, signaling to cybercriminal syndicates that cross-border cooperation among global law enforcement agencies is stronger and more synchronized than ever before.
