September 27, 2026
FBI and Japan warn North Korea's "WaterPlum" group is draining crypto wallets via fake job interviews

The FBI, Japan's National Police Agency, and cybersecurity partners in the US, Australia and Germany published a joint advisory on September 18 naming "WaterPlum" — also known as "Contagious Interview" — a North Korean state-linked group that has infiltrated at least 30,000 devices in more than 100 countries and stolen cryptocurrency wallet credentials from over 7,000 victims.
What happened
According to the advisory, WaterPlum operates by posing as recruiters for AI, cryptocurrency, or NFT companies on job boards, freelance marketplaces, and social media. Targets — mostly software developers and IT freelancers — are drawn into a fake interview process that ends with a "technical assignment": downloading and running a code package hosted on legitimate developer platforms like GitHub. The agencies say the group has transferred the equivalent of $10.71 million in stolen crypto to North Korea so far.
How the scam works
The advisory describes the interview itself as the delivery mechanism. Actors ask candidates to fix a supposed bug or complete a coding task, sometimes claiming a fault in the video-call software to justify the download. AI face-swapping is reportedly used to disguise the actors as legitimate employers during calls. The downloaded packages carry malware families the advisory names as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which install remote-access backdoors and harvest browser credentials, keystrokes, clipboard data, and — specifically — cryptocurrency wallet private keys and seed phrases stored on the victim's machine.
WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.
Why it matters
This isn't a phishing email or a fake exchange login page — it targets people who write code for a living, using their own professional workflow (cloning a repo, running an assignment) as the infection point. Anyone whose device also holds a software wallet is exposed the moment the malicious package runs. The advisory also notes some WaterPlum operatives work directly as contracted IT staff, funneling both salaries and harvested data back to the regime, which blurs the line between "job scam" and "insider access."
What to do
The agencies recommend running any unsolicited technical assignment in a sandbox or disposable virtual machine — never on a device that also holds a wallet, private keys, or a browser session with saved credentials — and treating unusually easy interview processes, requests for cryptocurrency payment, or reluctance to meet on camera as red flags. If you've already run an unfamiliar assignment file on a machine that also held a seed phrase or exchange session, the wallet and any accounts accessed from that device should be treated as compromised. WalletRecover's guide on what to do after a crypto scam covers the immediate steps for securing what's left and reporting the incident.
— WalletRecover Team