North Korean Hackers Use Fake Job Interviews to Infect 30,000 PCs, Steal $10.7M Crypto
Key Takeaways North Korean-linked threat actors, collectively known as WaterPlum and operating under the campaign name “Contagious Interview,” have exploited fake job interviews to infect...
Key Takeaways
- North Korean-linked threat actors, collectively known as WaterPlum and operating under the campaign name “Contagious Interview,” have exploited fake job interviews to infect over 30,000 computers across more than 100 countries.
- The campaign, active from December 2025 to July 2026, resulted in the theft of approximately $10.7 million in cryptocurrency from over 7,000 digital wallets.
- Targets were primarily software developers, lured into downloading and executing malicious files disguised as coding tasks or interview software.
- The attack not only compromises individual systems and crypto wallets but also poses a significant supply chain risk by using compromised developers as entry points to their employers’ or clients’ networks.
- The threat actors utilized sophisticated tactics, including AI face-swapping during video interviews and the operation of “laptop farms” to obscure their true location.
A sophisticated cybercrime operation attributed to North Korean state-sponsored hackers, known as WaterPlum, has successfully compromised more than 30,000 personal computers across over 100 nations. This extensive campaign, dubbed “Contagious Interview,” leveraged convincing fake job interviews to trick software developers into installing malware, leading to the theft of an estimated $10.7 million in cryptocurrency from over 7,000 digital wallets. The attacks took place between December 2025 and July 2026.
Table Of Content
The Internet Crime Complaint Center (IC3) has highlighted this deceptive tactic in its guidance regarding North Korean IT worker activities. According to an IC3 report, threat actors are exploiting the trust inherent in hiring processes to implant malicious software onto systems containing sensitive data.
Beyond direct financial theft, the campaign introduces a critical secondary risk: a compromised developer can inadvertently become a conduit for further intrusions into their employer’s or client’s networks. Stolen data, including browser login credentials, cryptocurrency wallet keys, identity documents, screenshots, and project files, can facilitate future theft, extortion attempts, or direct access to corporate infrastructures.
North Korean WaterPlum Hackers Infect 30,000 PCs
The WaterPlum group initiates contact with potential victims through various platforms, including social media, professional job boards, and freelance marketplaces. They impersonate legitimate employers and then instruct candidates to complete a simulated coding challenge or troubleshoot a fabricated issue with interview software. This approach mirrors other “fake recruiter” schemes where a standard technical assessment is weaponized.
Instead of a benign task, candidates are directed to download and execute a malicious project, software package, or file. These files are typically laden with various malware strains, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. These tools are designed to establish initial footholds, maintain persistent remote access, and exfiltrate sensitive information from infected systems.
One notable malware, StoatWaffle, can be embedded within projects themed around blockchain technology. It exploits a specific Visual Studio Code configuration to execute malicious code automatically when a victim opens and “trusts” the project folder. The attackers have also been observed employing advanced social engineering techniques, such as AI face-swapping during video interviews, to enhance their credibility. This tactic underscores that even a seemingly professional recruitment process does not guarantee the safety of downloaded content.
The repercussions of such compromises extend far beyond individual financial losses. Credentials pilfered from developers can expose entire organizations—employers, clients, or contractors—to intellectual property theft and widespread network breaches. Furthermore, stolen identity documents could enable North Korean IT workers to assume false identities, securing legitimate contracts and generating foreign income for the regime.
Laptop Farms Broaden Risk
Authorities have connected segments of this illicit activity to North Korean IT workers who operate under fabricated identities. These individuals utilize “laptop farms”—physical locations equipped with numerous computers managed remotely—alongside virtual private servers and local facilitators to obscure their true geographic location. This infrastructure allows them to conduct their malicious operations while maintaining a facade of legitimacy.
An advisory detailed how Japanese authorities dismantled a laptop farm linked to one such enabler. Investigations revealed that WaterPlum operatives and suspected North Korean IT workers used identical IP addresses when accessing these laptop farms, interacting with crowdsourcing services, and even applying for positions at a Japanese cryptocurrency exchange. This overlap provided crucial evidence linking the various activities.
What You Should Do
- For Employers:
- Scrutinize unusual recruitment details and treat them as potential security threats.
- Verify all contact information for recruiters and applicants independently.
- Encourage in-depth discussions with candidates about their experience to detect inconsistencies.
- Remain vigilant for discrepancies in claimed skills, location, language proficiency, or payment requests.
- Implement robust vetting processes for all contractors and employees, especially those with privileged access.
- Limit contractor access to essential resources and revoke accounts and sessions immediately upon suspicion.
- For Candidates/Developers:
- Never execute unknown code on personal devices or systems containing cryptocurrency, sensitive data, or corporate access.
- Always test untrusted projects or code in an isolated, sandboxed environment.
- Thoroughly inspect all downloaded files and projects for obfuscated or unreadable content.
- When using Visual Studio Code, avoid opening unfamiliar projects outside of Restricted Mode.
- If you suspect an infection, immediately disconnect the device from the internet.
- In case of suspected wallet compromise, create a new wallet on a separate, clean device, transfer all assets, store the new seed phrase offline, back up critical files, and perform a full system reset on the compromised machine.
This campaign underscores a persistent threat to developers: the allure of a promising job opportunity can normalize risky behavior, such as downloading and executing untrusted code. This method is analogous to other malware campaigns, like the broader Contagious Interview operation, which similarly exploits the hiring process to deliver credential-stealing software.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| Malware family | BeaverTail | JavaScript-based malware delivered through malicious packages and developer projects |
| Malware family | InvisibleFerret | Python-based backdoor used to access compromised systems |
| Malware family | OtterCookie | JavaScript remote-access and information-stealing malware |
| Malware family | OtterCandy | Malware combining OtterCookie and RATatouille capabilities |
| Malware family | StoatWaffle | Modular Node.js loader, credential harvester and remote-access malware |
| File name | .vscode/tasks.json |
Visual Studio Code task configuration file that can trigger malicious code execution when an unsafe project folder is trusted |
| Suspicious command string | curl |
Command string cited by the advisory as a warning sign in untrusted scripts |
| Suspicious command string | base64 |
String that can indicate encoded or concealed script content |
| Suspicious command string | -enc |
Common encoded-command parameter cited in the advisory |
| Suspicious command string | mshta |
Script execution utility cited as a suspicious string in unknown commands |
| Suspicious command string | Invoke-WebRequest -Uri |
Download command pattern that should be reviewed before execution |
| Suspicious command string | iwr -uri |
Shortened download-command pattern cited in the advisory |
| Suspicious command string | hidden |
String that can indicate an attempt to conceal command execution |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.