°C
Air:
GOLD73,245 0.25%
SILVER84,520 0.29%
USD83.25 0.12%
EUR90.45 0.08%
GBP105.6 0.15%
WaterPlum Hackers Use Fake Job Interviews and AI to Target IT Professionals and Steal Millions in Cr
Cyber Security

WaterPlum Hackers Use Fake Job Interviews and AI to Target IT Professionals and Steal Millions in Cr

0 views
Text Size:

The joint advisory, published on September 18, 2026, said WaterPlum actors pose as prospective employers and recruiters to approach technology professionals around the world.

WaterPlum Fake Job Interview Cyber Scam

Cybersecurity agencies from Japan, the United States, Australia and Germany have issued a joint warning about a North Korea linked cyber group known as WaterPlum, which is also commonly referred to as Contagious Interview. The group has been targeting software developers, web designers, engineers and other IT professionals by disguising cyberattacks as genuine employment opportunities.

The joint advisory, published on September 18, 2026, said WaterPlum actors pose as prospective employers and recruiters to approach technology professionals around the world. The attackers reportedly use attractive job offers and recruitment processes to gain the trust of potential victims.

According to the advisory, the group frequently impersonates companies operating in areas such as artificial intelligence, cryptocurrency and non-fungible tokens. Recruitment services and online employment platforms have also been used as part of the approach.

The campaign takes advantage of the normal hiring process followed by technology companies. A candidate may receive what appears to be a legitimate job opportunity and then be asked to participate in an online interview, complete a coding assignment or troubleshoot a technical problem.

During this process, the attackers may ask the applicant to download or execute files required for the supposed interview or technical task. According to the international advisory, those files can contain malicious software designed to gain access to the victim's computer.

The malware identified in the campaign includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. These malicious programs can be used to steal sensitive information and maintain access to compromised systems.

The advisory said WaterPlum has infected at least 30,000 devices in more than 100 countries. The campaign has targeted individual IT professionals in countries including Japan, the United States and European nations.

Authorities also reported that information or funds were taken from more than 7,000 cryptocurrency wallets. The attackers transferred approximately 1.7 billion Japanese yen in cryptocurrency, equivalent to about 10.71 million US dollars, to North Korea, according to the joint assessment.

The scale of the operation makes the campaign particularly significant for software developers and technology professionals who regularly participate in remote interviews and online coding tests.

The attackers' method is based on exploiting trust rather than simply sending conventional phishing messages. Job seekers are more likely to download files or follow technical instructions when they believe they are communicating with a potential employer.

The use of AI technology has also been reported in some of the group's activities. Investigators observed WaterPlum members using AI based face swapping software during online interviews. In some cases, the attackers reportedly switched off their video after a short period and claimed that they were experiencing network problems.

The advisory also described the use of text to speech and translation tools. Investigators observed actors practising Japanese pronunciation using text to speech software and using free machine translation and AI services.

These techniques can make fake interviews appear more convincing and can make it harder for applicants to immediately identify that they are dealing with an impersonator.

The cyber campaign does not only create a risk of direct cryptocurrency theft. Once malware gains access to a computer, attackers may also obtain browser credentials, passwords, cryptocurrency wallet information, clipboard data, screenshots and other files stored on the device.

Sensitive identity documents can also become targets. The advisory said stolen identification images could potentially be used for impersonation in other operations.

For IT professionals, the risk can extend beyond their personal computers. If a compromised device is subsequently connected to an employer's network, attackers could potentially use the access to target company systems and information.

The authorities warned that successful infections could provide opportunities for further intrusion into organisations that employ targeted developers. Potential consequences include theft of intellectual property, sensitive company information and additional credentials.

The WaterPlum campaign also appears to overlap with another North Korea linked activity involving IT workers obtaining employment using false identities.

The Japanese and US authorities assessed that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is subordinate to the Central Committee of the Workers' Party of Korea.

Investigators also identified connections involving the same internet addresses being used to access laptop farms, crowdsourcing services and employment applications.

A laptop farm is a setup in which computers belonging to a person or intermediary are located in one place and remotely controlled by workers elsewhere. According to the advisory, such arrangements can allow North Korean IT workers to obtain and perform contracts while disguising their actual locations.

The investigation also uncovered activity involving a Japanese cryptocurrency exchange. In 2025, a person suspected of being a North Korean IT worker applied for an engineering position at the exchange using a forged resume.

Investigators said the application contained several warning signs, including an unusually broad list of technical skills and an employment and education history spanning multiple countries. During the interview, the applicant's claimed background and technical abilities reportedly did not fully match.

The company identified the application as suspicious and did not hire the applicant. Authorities said no damage occurred in that particular case.

The international advisory has therefore urged companies and job seekers to take additional precautions during recruitment.

For applicants, one important warning sign is being asked to download unfamiliar software or code as part of an interview. Candidates should be particularly careful when a supposed recruiter asks them to execute unknown programs or technical files on their personal computer.

Job seekers should also verify the identity of recruiters and the company offering the position. Checking the official company website, recruitment contacts and the advertised vacancy through independent channels can help determine whether an opportunity is genuine.

Applicants should be cautious about technical tests hosted through unfamiliar websites or repositories. A legitimate coding assignment does not automatically make every file safe, and candidates should avoid executing untrusted code on computers containing sensitive personal or financial information.

The advisory also recommends that companies strengthen their recruitment verification procedures. Employers can verify an applicant's qualifications, contact details, claimed location and technical experience before providing access to company systems.

Companies should also be cautious when candidates refuse normal verification procedures or provide inconsistent information about their location and employment history.

The WaterPlum case demonstrates how cybercriminal groups can combine social engineering, malware and fake recruitment processes to target highly skilled professionals.

The warning is particularly relevant as remote employment and online technical interviews have become common across the global technology industry. Job seekers often need to download development tools, access code repositories and participate in video calls as part of recruitment, creating opportunities for attackers to disguise malicious activity as normal hiring procedures.

Authorities have advised individuals and organisations to remain alert to suspicious recruitment requests and to use appropriate cybersecurity controls.

The joint advisory also recommends avoiding the execution of untrusted code on computers used to store cryptocurrency assets or sensitive personal information. Organisations should maintain appropriate endpoint security and restrict access to sensitive systems.

If a person suspects that a computer has been compromised, authorities recommend disconnecting the affected device from the internet and taking appropriate security measures. Users should also consider that credentials or sensitive information may already have been exposed.

The investigation into WaterPlum remains part of a wider international effort to disrupt North Korea linked cyber operations. Japan, the United States, Australia and Germany said they would continue cooperation and information sharing to address these activities.

For Indian IT professionals and job seekers, the warning is also relevant because the campaign targets technology workers internationally rather than being limited to one country. Remote recruitment platforms, freelance marketplaces and online professional networks can all be potential channels through which fake employment offers are delivered.

The central warning is straightforward. A job interview should not require a candidate to blindly execute unfamiliar software or code on a personal computer. Attractive salaries, well-designed company profiles and convincing online interviews do not by themselves prove that a recruiter or job opportunity is genuine.

WaterPlum's reported campaign shows how attackers can use the normal hiring process as a pathway to compromise devices and steal sensitive information. Job seekers should therefore verify recruiters, independently confirm vacancies and treat unexpected downloads or technical instructions with caution.

The international advisory provides a reminder that cybersecurity risks can begin even before a person joins a company. A fake job opportunity can become an entry point for malware, identity theft and cryptocurrency theft if basic security precautions are ignored.

According to the international advisory, those files can contain malicious software designed to gain access to the victim's computer.