Crypto: fake interviews install malware
WaterPlum primarily targets web developers, engineers and blockchain or Web3 specialists. Bref Crypto had already documented another branch of this North Korean strategy, in which genuine foreign developers are recruited to attend interviews on behalf of operators linked to the regime.
Here, the roles are reversed. The candidate becomes the target.
Fake recruiters contact their victims through social media, job platforms, freelance marketplaces or recruitment services. During the interview, they ask candidates to run a programming project or download a patch supposedly designed to fix a video-conferencing error. The malicious files may be hosted on development platforms that are entirely familiar to programmers.
The official joint advisory cites several malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Some are hidden in NPM packages. StoatWaffle can even use fake blockchain projects opened in Visual Studio Code to trigger the execution of malicious code.
A simple technical test then becomes a backdoor.
Private keys, cookies and screenshots
Once the machine has been compromised, WaterPlum deploys remote access trojans and infostealers. The tools look for far more than a few passwords.
Authorities cite credentials stored in browsers, clipboard data, keystrokes, screenshots, identity documents, as well as private keys and seed phrases for crypto wallets. The data can then be sent to a command-and-control infrastructure remotely controlled by the attackers.
Between December 2025 and July 2026, this operation allegedly compromised at least 30,000 devices in more than 100 countries. More than 7,000 wallets had their funds or credentials stolen. The value of the cryptocurrency transferred to North Korea reached at least 1.7 billion yen, or approximately $10.71 million.
The money is only part of the problem. A developer’s machine can also become an entry point into their employer’s systems. WaterPlum may then seek source code or intellectual property, or move laterally through internal systems.
Bref Crypto had already shown how malware could target wallets and exchange accounts at the same time. WaterPlum adds a particularly effective weapon: the trust placed in a recruiter who appears to be offering a perfectly credible job.
North Korea industrializes recruitment
The attribution is not based solely on private researchers. The FBI and Japanese police believe that WaterPlum and some North Korean IT workers operate under the 313 General Bureau, which is attached to the Munitions Industry Department of the Workers’ Party of Korea. The advisory was also co-signed by Australian and German agencies.
The strategy now goes beyond the conventional hacking of an exchange. On one side, North Korean operators pose as candidates to join foreign companies. On the other, WaterPlum poses as the employer in order to infect genuine candidates.
Same social infrastructure. Two different directions.
This model is part of a much larger cyber economy. Groups linked to North Korea have already stolen several billion dollars in crypto, with the $1.5 billion Bybit hack standing out as 2025’s most spectacular case.
WaterPlum nevertheless shows that there is no need to find a billion-dollar vulnerability.
A fake GitHub repository may be enough.
An NPM package.
A React exercise.
A “problem” with the camera during the interview.
For crypto and AI developers, recruitment itself is now an attack surface. The official advisory notably recommends never blindly running code provided during an interview, verifying the company’s identity and, when an infection is suspected, backing up essential data before carrying out a full system reset, because the malware may maintain persistence on the machine.
The blockchain may be perfectly secure.
If the person holding the keys runs the wrong file during a job interview, WaterPlum no longer needs to attack it.