Summary
- A North Korean hacking group known as WaterPlum is posing as recruiters to plant malware on software developers’ computers around the world through fake job interviews. Running a single “coding test” file can give the hackers access to the computer, its cryptocurrency wallets and potentially the systems of an employer.
Editor's note: this story was translated from the original VOA Korean article.
What is WaterPlum?
The name that seven intelligence and law enforcement agencies from the United States, Japan, Australia and Germany use for this North Korean hacking group in a joint warning.
The U.S. Federal Bureau of Investigation (FBI) and the U.S. Department of Defense Cyber Crime Center (DC3); Japan’s National Police Agency and National Cybersecurity Office; the Australian Cyber Security Centre; and Germany’s Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV) issued the joint warning. The group is also commonly known as “Contagious Interview.” As that name suggests, the job interview itself is the weapon.
What the hackers are up to
WaterPlum poses as recruiters for AI and cryptocurrency companies, then gets developers to run a malicious file during the hiring process, often presented as a coding test. From about December 2025 through July 2026 the group compromised at least 30,000 computers in more than 100 countries, took funds or account credentials from more than 7,000 cryptocurrency wallets and transferred at least $10.71 million in cryptocurrency to North Korea.
Why it matters
The danger can extend beyond the person taking the interview. The hackers seek cryptocurrency and personal information, while access to a developer’s computer may also open a path into the company or client the developer works for.
Matthew B. Welling, a lawyer at the U.S. firm Holland & Knight who has examined the North Korean IT worker problem, said the damage to a company may not come one piece at a time.
“Liability can also arise under various contracts or other regulations. These risks are not isolated but can compound simultaneously,” Welling told VOA. “Companies can suffer multiple potential damages all at once, including contractual liability, reputational damage, and the exposure of systems, intellectual assets, and other information.”
Your browser doesn’t support HTML5
Matthew B. Welling
How does the fake interview work?
WaterPlum members pose as recruiters or prospective employers, often using the names of legitimate artificial intelligence and cryptocurrency businesses. They contact developers through job sites, social media and freelance platforms.
The applicant is asked to complete a technical interview or coding assignment. At some point, the supposed recruiter instructs the applicant to download and run a file. In other cases, the instruction is presented as a way to fix a problem with the video interview.
The file can install malicious software. The attackers can then search the computer for passwords, cryptocurrency wallet information, identity documents and other valuable data.
The key moment:
A job applicant may think they are demonstrating their skills. By running the file, they may instead give the attackers access to their computer.
How widespread is it?
WaterPlum exploited at least 30,000 computers in more than 100 countries from about December 2025 through July 2026. The attackers took funds or account credentials from more than 7,000 cryptocurrency wallets. They also transferred at least $10.71 million in cryptocurrency to North Korea.
Workers use false identities to obtain remote contracts with foreign companies and send earnings to North Korea.
What does this have to do with North Korean IT workers?
North Korea has a second way to profit from technology jobs: workers use false identities to obtain remote contracts with foreign companies and send earnings to North Korea.
The FBI and Japan’s National Police Agency assess that WaterPlum members and some North Korean IT workers operate under the same bureau within the Workers’ Party of Korea. The two groups also used some of the same internet addresses when accessing remotely managed computers and applying for jobs.
Some WaterPlum members performed contracted IT work themselves. Identity documents stolen in a fake interview could also help North Korean workers impersonate someone else when seeking a job.
The bigger picture
One scheme targets a real developer with a fake job offer. Another places a North Korean worker in a real job under a false identity. Stolen identities and access credentials can help connect the two.
Mauro Rozanowski, founder of the cybersecurity firm BCA LTD, set up a fake cryptocurrency startup and interviewed applicants suspected of being North Korean IT workers. In an interview with VOA, he warned of the hacking threat posed by North Korean IT workers who land jobs under false identities.
“You will even see their names don’t match real names in any database, and sometimes they copy entire resumes from real candidates, so they are pretty easy to spot in interviews,” Rozanowski told VOA.
Your browser doesn’t support HTML5
Mauro Rozanowski
Why should companies care?
A developer’s computer may hold access to company code, shared files or accounts. If WaterPlum compromises that computer, the attackers may be able to reach an employer or client as well.
That can open the door to theft of trade secrets and deeper movement through company systems. In some cases, North Korean IT workers have used their access to extort a company or disrupt its website.
That makes the hiring process a security issue for both sides: applicants deciding whether to run a coding test, and companies deciding whom to hire and what systems that person can access.
If WaterPlum compromises that computer, the attackers may be able to reach an employer or client as well.
What do experts recommend?
Security experts urge developers to be suspicious when an unfamiliar recruiter asks them to run code or download a project during an interview. A request to enter a command to “fix” a video call is another warning sign.
They recommend checking unfamiliar code before running it and using a separate, isolated environment for untrusted tests. Companies should limit access to sensitive systems and verify applicants’ identities and claimed experience.
For job seekers and employers alike, running a single file during what looks like a routine interview can expose cryptocurrency, identity documents and access to company systems. That is why experts' advice comes down to verifying first: developers should check unfamiliar code and test it only in an isolated environment, and companies should verify applicants' identities and limit what new hires can access. The cost of one fake coding test may not stop with the applicant.