Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
September 18, 2026 — The FBI and international law enforcement and intelligence partners are warning governments, businesses, cryptocurrency organizations, software developers, and technology professionals about a North Korean cyber operation that authorities say has compromised at least 30,000 devices across more than 100 countries and targeted thousands of cryptocurrency wallets.
The campaign is attributed to a North Korean cyber actor group identified as WaterPlum, commonly referred to within the cybersecurity community as “Contagious Interview.” The operation targets software developers, web professionals, cryptocurrency specialists, blockchain engineers, and other information technology workers by disguising malicious cyber activity as legitimate recruitment and employment opportunities.
The September 18 advisory was issued through cooperation involving Japan’s National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre, Germany’s Federal Intelligence Service, and Germany’s Federal Office for the Protection of the Constitution.
Authorities assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is subordinate to the Central Committee of the Workers’ Party of Korea. The attribution places the operation within a broader North Korean structure connected in the advisory to cyber operations, foreign-currency generation, and activities that may violate domestic laws and sanctions against the DPRK.
Investigators say WaterPlum actors commonly pose as recruiters or representatives of legitimate technology companies. Artificial intelligence firms, cryptocurrency businesses, non-fungible token companies, recruitment services, freelance marketplaces, social-media platforms, and online job sites have all been used as part of the operation.
The attackers approach job seekers with what appear to be legitimate technical positions. Targets may then be instructed to participate in virtual interviews or complete coding assignments. During those interactions, the victim is directed to download files, open programming projects, execute software, or troubleshoot a supposed problem with a video-conferencing platform.
That is where the recruitment process can become a cyber intrusion.
According to the joint advisory, attackers have placed malicious code inside Node Package Manager, or NPM, packages, development repositories, and programming projects. Malware associated with the campaign includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, along with related variants.
BeaverTail has been identified as JavaScript-based malware concealed inside NPM packages distributed through developer platforms. InvisibleFerret functions as a Python-based backdoor. OtterCookie operates as a JavaScript remote-access Trojan and information stealer. OtterCandy combines features associated with OtterCookie and RATatouille. StoatWaffle is a modular Node.js malware family capable of loading additional malicious components, harvesting credentials, and maintaining remote access through malicious Microsoft Visual Studio Code projects.
Once a victim executes the malicious content, WaterPlum actors can establish backdoor access to the device. Remote-access Trojans allow the attackers to maintain persistence, communicate with infected systems, and move through compromised environments.
Information-stealing malware can then collect sensitive data and transmit it to command-and-control infrastructure controlled by the attackers.
The information targeted can include browser-stored usernames and passwords, clipboard contents, recorded keystrokes, screenshots, cryptocurrency wallet private keys, wallet seed phrases, files stored locally or in shared folders, driver’s license images, passport images, and other identity documents.
The threat does not necessarily end with the developer who initially opens the malicious project.
Authorities warn that compromising a software professional can provide an entry point into that person’s employer, clients, contractors, or business partners. Successful infections can create opportunities for espionage, theft of proprietary source code, intellectual property theft, credential theft, extortion, and lateral movement deeper into corporate networks.
The scale described by investigators is substantial.
Between approximately December 2025 and July 2026, WaterPlum is assessed to have exploited at least 30,000 computers in more than 100 countries, including systems in Japan and the United States. Authorities said the campaign primarily targeted web designers, engineers, cryptocurrency specialists, blockchain professionals, and workers involved in Web3 technologies.
Investigators identified funds or account credentials taken from more than 7,000 cryptocurrency wallets. At least 1.7 billion Japanese yen, approximately $10.71 million, in cryptocurrency was transferred from victims for the benefit of the Democratic People’s Republic of Korea, according to the advisory.
The operation overlaps with another North Korean activity that U.S. authorities have been warning about for years: fraudulent remote IT workers obtaining legitimate employment using false or stolen identities.
The advisory describes so-called “laptop farms,” locations where computers supplied by employers are physically housed in one country while North Korean workers remotely control them from another. These locations are often operated from the residence of an intermediary who provides computers, internet access, identity documents, financial accounts, or other logistical support.
North Korean IT workers may actually be located in North Korea, China, Russia, Africa, or Southeast Asia while presenting themselves to employers as applicants living somewhere else. Virtual private servers and remote-access technology can be used to conceal the workers’ true physical locations while they perform contracted IT work.
Japan has now documented what authorities described as the country’s first successful identification, investigation, and dismantling of a laptop farm operated by an enabler. Investigators also obtained evidence showing that individuals associated with the activity transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside Japan.
The FBI said it continues identifying and prosecuting U.S.-based individuals who provide facilitation services to North Korean IT workers. Those investigations have involved multiple jurisdictions and different forms of assistance used to conceal the true identities or physical locations of remote workers.
The Bureau says cooperation from victim companies has become an important part of disrupting schemes designed to infiltrate private businesses and redirect employment income toward the North Korean government and military.
The advisory also warns that some North Korean IT workers have gone beyond earning salaries under fraudulent identities.
Investigators documented an incident in which a North Korean IT worker extorted a company over payment and published proprietary source code online. In another case, a worker hired to maintain a website defaced the company’s site and rendered it inaccessible.
The FBI issued separate guidance in 2025 warning businesses that North Korean remote workers had engaged in data theft and extortion after obtaining employment. The Bureau advised companies to strengthen identity verification, examine remote-worker network activity, review access to private code repositories, scrutinize employment histories, and investigate unusual changes involving addresses, payment methods, devices, and online accounts.
The September 2026 WaterPlum advisory provides a detailed example of how fraudulent recruitment can also work in the opposite direction: rather than North Korean operatives trying to get hired, the operatives can pose as employers and attack legitimate job applicants.
The report describes a May 2025 incident involving a Japanese cryptocurrency exchange that received an application for an engineering position from an individual believed to be a North Korean IT worker. The applicant used a forged résumé and connected to the company’s recruitment system through a VPN.
Investigators said the résumé claimed an unusually broad range of programming, blockchain, cryptocurrency, and cloud-computing expertise. The applicant claimed to have attended a European university and worked in several cities across Europe and Asia in rapid succession.
During a video interview, the applicant claimed to have been born in Malaysia and to reside in Finland. The applicant identified Malay and Chinese as native languages, but authorities said the individual’s English ability and technical responses did not correspond with the extensive academic and professional background claimed on the résumé.
The company identified the inconsistencies and did not hire the applicant. Authorities reported no resulting damage.
Other indicators observed during suspected North Korean IT worker interviews include resistance to in-person meetings, requests for cryptocurrency payments, repeated glances toward another monitor, background voices suggesting additional people may be assisting, and recurring video or audio interruptions.
The advisory warns employers that multiple people may work behind the scenes during an interview while one applicant appears on camera. Employers are encouraged to require detailed explanations of skills listed on résumés, verify professional certifications, independently confirm education and employment histories, and ask applicants questions that can help establish whether their claimed location and background are genuine.
Investigators have also observed WaterPlum members using AI face-swapping software during online interviews. In some cases, the actors disabled their cameras after several minutes and encouraged the target to do the same while claiming network problems. Authorities also observed actors practicing Japanese pronunciation using text-to-speech technology and consistently using free machine-translation and artificial-intelligence services.
The FBI has separately warned that North Korean IT workers have used AI and face-swapping technology during job interviews to conceal their identities, reinforcing concerns that conventional video verification alone may no longer be sufficient for remote hiring.
Investigators also identified technical overlap between WaterPlum cyber operators and North Korean IT workers. According to the advisory, both groups used the same IP addresses when accessing laptop farms, using crowdsourcing services, and applying for employment at the Japanese cryptocurrency exchange.
That overlap is significant because it connects two activities that can appear separate on the surface: malware campaigns targeting technology professionals and fraudulent employment operations designed to generate foreign currency.
The FBI has described North Korea’s remote IT worker network as a broader counterintelligence and national security concern because workers can gain legitimate access to corporate systems while generating revenue for the regime. The Bureau says organizations ranging from private companies to U.S. government entities have unknowingly employed individuals participating in the scheme.
Security teams and individual developers are being urged to treat unexpected coding assignments and software projects from recruiters with the same caution applied to suspicious attachments and phishing links.
The WaterPlum advisory recommends avoiding execution of untrusted code on systems containing cryptocurrency assets or sensitive personal information. Unknown projects should be examined inside isolated environments or virtual machines, and developers should inspect code for obfuscated or unreadable components before execution.
Organizations are also advised to deploy endpoint detection and response systems, restrict employee access to the minimum information necessary for assigned work, promptly revoke accounts and sessions when a contractor is suspected of malicious activity, and examine Visual Studio Code projects before granting them trusted status.
The advisory specifically warns developers about malicious “.vscode/tasks.json” files capable of automatically executing code when a project is opened and trusted. Unknown projects should be opened in Visual Studio Code’s Restricted Mode until their contents have been examined.
If a device is suspected of being compromised, authorities recommend disconnecting it from the internet immediately. Victims should assume sensitive information may already have been stolen even if malware is later detected and removed.
For cryptocurrency users, that can mean creating a new wallet from a separate, trusted device, transferring assets away from potentially compromised wallets, and storing the replacement seed phrase offline. Authorities also recommend backing up necessary information and fully resetting an affected operating system when persistent malware cannot be ruled out.
The WaterPlum operation illustrates how North Korean cyber activity can reach targets through recruitment, remote employment, software-development workflows, and cryptocurrency-related activity. The target may now be an individual developer searching for work, a company hiring a remote programmer, a cryptocurrency exchange reviewing an applicant, or a household unknowingly hosting computers that form part of an international laptop farm.
A seemingly routine hiring process can provide the entry point.
The FBI and its international partners warn that the techniques documented in the advisory represent only known examples and that the actors continue modifying their methods. The threat combines social engineering, malware deployment, identity fraud, remote employment, cryptocurrency theft, extortion, and international financial movement into an operation that can reach both individual professionals and the organizations connected to them.
The central warning is direct: technical professionals should not assume a coding test is safe because it arrives through a professional recruitment channel, and businesses should not assume a remote employee is who the résumé, video call, or network connection claims them to be.
For WaterPlum, the hiring process itself has become part of the attack surface.
National Police Agency of Japan (NPA), National Cybersecurity Office of Japan (NCO), Federal Bureau of Investigation (FBI), U.S. Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Germany’s Federal Intelligence Service (BND), and Germany’s Federal Office for the Protection of the Constitution (BfV). (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified




Thank you for sharing this important cybersecurity warning. The scale and sophistication of the campaign are deeply concerning, especially because it exploits something as ordinary and trusted as a job interview.