Mastodon

Fake Job Interview Malware: How North Korea Targets Devs

Diagram showing a fake job interview scam delivering malware through booby-trapped developer code
Spread the love

North Korea’s Fake Job Interviews Have Now Infected 30,000 Devices in 100+ Countries — And the Trick Is Barely Technical

On September 18, six government agencies across four countries put their names on one advisory. That alone should tell you how serious this has become.

The group — tracked as WaterPlum, better known in security circles as “Contagious Interview” — doesn’t hack its way in. It talks its way in.

Diagram showing a fake job interview scam delivering malware through booby-trapped developer code
IMAGE CREDIT : BBC

Here’s how the operation actually works:

  • → Operators pose as recruiters for legitimate AI, cryptocurrency, or NFT companies, reaching out through social media, job boards, gig platforms, and freelance marketplaces
  • → Targets are invited to a technical interview or coding test — a completely normal ask for any developer job
  • → During the “interview,” the video call conveniently breaks, and the recruiter asks the candidate to run a quick fix for the conferencing plugin — or the coding assignment itself is a booby-trapped repository
  • → That one command execution installs the actual payload — five different malware families (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) that steal credentials, clipboard data, keystrokes, crypto wallets, and identity documents
  • → Investigators say operators even use AI face-swapping software during the video calls, then conveniently “lose” their camera feed and blame network issues

The numbers, from December 2025 to July 2026 alone:
→ 30,000+ devices infected across 100+ countries
→ 7,000+ cryptocurrency wallets compromised
→ $10.71 million funneled back to North Korea

The advisory — jointly issued by Japan’s National Police Agency, the FBI, the US Defense Department’s Cyber Crime Center, Australia’s ACSC, and Germany’s BND/BfV — also connects WaterPlum directly to North Korea’s fraudulent remote-IT-worker scheme. The stolen identity documents don’t just sit in a database — they’re reused by North Korean operatives to impersonate the victims and land real remote jobs at Western companies, generating ongoing foreign currency for the regime. Both operations reportedly trace back to the same unit: the 313 General Bureau of the Munitions Industry Department.

Here’s what makes this genuinely hard to defend against: there’s no exploit to patch, no software flaw to fix. The entire attack runs on a social process every developer has been trained to trust — a recruiter reaching out, a technical interview, a coding assignment. WaterPlum didn’t find a vulnerability in code. It found one in professional courtesy.

If you’re a developer, freelancer, or anyone in crypto/Web3 currently job-hunting: never run code, “fixes,” or scripts sent to you mid-interview, no matter how legitimate the company looks or how normal the request sounds.

Has anyone in your network run into a recruitment process that felt slightly off like this?

#Cybersecurity #NorthKorea #WaterPlum #ContagiousInterview #InfoSec #TechNews

Sandeep Raiza

Sandeep RaizaContent Writer, Website Designer, SEO Strategist, and WordPress Expert AI specialist delivering impactful digital solutions that drive business growth.Combining creative storytelling with technical expertise.

Spread the love

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top