Breaking NewsUpdated as information becomes available
News·Threat Analysis·25 September 2026·Breaking

Fake job interviews infected 30,000 devices, FBI-led advisory says

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

Mark Fermor
Mark FermorCTO, CMO & Founder, Firevault
5 min read
Share
A fake technical job interview on a developer laptop sends malicious code towards a workstation while a physically disconnected data store remains protected
A fake technical job interview on a developer laptop sends malicious code towards a workstation while a physically disconnected data store remains protected

Why it matters

What this means for organisations holding critical data

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

What the agencies reported

A joint advisory published on 18 September by cyber and intelligence agencies in Japan, the United States, Australia and Germany says a North Korean-linked campaign has infected at least 30,000 devices in more than 100 countries.

The agencies call the group WaterPlum. Security researchers more commonly track the activity as Contagious Interview. According to the advisory, the actors pose as recruiters or prospective employers, often impersonating legitimate artificial intelligence, cryptocurrency and NFT businesses. They approach software developers and other IT professionals through social media, job sites, gig-work platforms and freelance marketplaces.

The figures are official assessments rather than independently audited totals. The advisory says the campaign has stolen funds or account credentials from more than 7,000 cryptocurrency wallets and transferred ¥1.7 billion, approximately US$10.71 million, in cryptocurrency assets to North Korea.

The interview is the delivery mechanism

The initial approach is designed to look like ordinary recruitment. During a video interview or coding assessment, the candidate is asked to download a project, repair a supposed conferencing fault or run code from a developer platform or repository.

The advisory names malicious npm packages, GitHub or Bitbucket repositories and Visual Studio Code projects as delivery routes. Malware families linked to the activity include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.

Once executed, the malware can create persistent remote access, steal browser credentials and cryptocurrency information, capture clipboard or keystroke data, take screenshots and collect identity documents. A compromised developer machine can also become a route into the organisation that employs that person.

That wider risk matters. This is not only a cryptocurrency theft campaign. The advisory warns that successful infections can create opportunities for espionage, intellectual property theft and lateral movement through corporate systems.

The laptop-farm connection

The same advisory connects WaterPlum infrastructure with North Korean IT workers who obtain legitimate-looking remote contracts using false or borrowed identities.

A laptop farm is a collection of employer-issued computers physically hosted by an enabler and remotely operated from another country. Japan says it identified and dismantled its first domestic laptop farm. The FBI says it continues to identify and prosecute US-based facilitators.

The Japanese National Police Agency and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of North Korea's Munitions Industry Department. That wording is an intelligence assessment, not a judicial finding.

What developers and employers should do

Developers should not run unfamiliar interview code on the same machine that holds employer access, personal data or cryptocurrency credentials. Unknown projects should be inspected before execution and, where testing is necessary, opened only in an isolated sandbox or virtual machine.

The advisory highlights suspicious commands and obfuscated scripts, including use of curl, base64, mshta, Invoke-WebRequest and hidden execution. A command containing one of these terms is not automatically malicious, but a recruiter who asks a candidate to run code they cannot explain should be treated as a serious warning sign.

Employers should verify remote applicants beyond identity documents and a short video call. The agencies recommend checking whether the applicant's network location broadly matches their claimed residence, testing detailed knowledge behind unusually broad CV claims, verifying qualifications and investigating payment requests involving cryptocurrency or accounts in another person's name.

Access must remain limited to what a contractor needs. If an identity or subcontracting concern emerges, revoke accounts and active sessions promptly rather than waiting for the investigation to finish.

If a machine may be infected

The advisory says to disconnect the affected device from the internet immediately. Removal of the detected malware is not enough, because information may already have been stolen and other persistence may remain.

Cryptocurrency assets should be moved to a new wallet created on a separate clean device, with the new seed phrase stored offline. Essential data should be recovered carefully before a full operating-system reset, and organisations should use endpoint monitoring to look for related behaviour elsewhere.

The Firevault view

The most important lesson is the trust boundary. A coding task can turn a developer's everyday workstation into an attacker-controlled foothold, and that workstation often holds access to source code, credentials, shared drives and recovery systems.

Detection and recruitment checks reduce the likelihood of compromise, but they do not answer the recovery question: what remains trustworthy after the machine and its connected identity have been exposed?

Critical recovery data held in Offline Secure Storage® is physically disconnected when it is not being used. Malware on a developer endpoint cannot browse, encrypt or exfiltrate a copy for which no network path exists. Organisations should keep the recovery copy outside the reach of developer tools, cloud identities and remote administration, then test that it can be restored without trusting the compromised estate.

Sources

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires