In May 2025 a Japanese cryptocurrency exchange interviewed a promising engineer. The resume listed more than ten programming languages, a comparable stack of blockchain and cloud skills, a European degree and a quick march of jobs across Europe and Asia. On the video call the applicant said he was born in Malaysia, lived in Finland, and spoke Malay and Chinese natively. The interview was in English, and his English did not match the career he had just described. He handled simple questions and could not speak to most of his own resume.
The exchange did not hire him. That is the rare ending.
Seven agencies, four countries, one recruiting pitch
That interview is one of the cases in a joint advisory published on 18 September by Japan's National Police Agency and National Cybersecurity Office, the US Federal Bureau of Investigation and Department of Defense Cyber Crime Center, Australia's ASD Cyber Security Centre, and Germany's BND and BfV. Their subject is the North Korean group Japan calls WaterPlum and most of the industry knows as Contagious Interview.
The numbers are the headline. The group has infected at least 30,000 devices across more than 100 countries and taken funds or account credentials from more than 7,000 cryptocurrency wallets. It has moved 1.7 billion Japanese yen in cryptocurrency, about 10.71 million US dollars, to North Korea. The NPA and the FBI assess that WaterPlum operators and some North Korean IT workers sit under the 313 General Bureau of the Munitions Industry Department, under the Workers Party of Korea's Central Committee.
The interview is the delivery mechanism
Operators pose as employers, often impersonating AI, cryptocurrency or NFT companies, and approach developers through social media, job boards, gig work sites and freelance marketplaces. Every pitch arrives at a technical interview or coding assignment, where the candidate is told to download and run a file, either to finish the exercise or to fix a glitch in the video call. Those files are malicious NPM packages carrying BeaverTail, InvisibleFerret, OtterCookie, OtterCandy or StoatWaffle.
StoatWaffle is the one to read twice: a modular Node.js family that ships inside blockchain-themed Visual Studio Code project repositories, embedding a configuration file that auto-runs code the moment the victim opens the folder and trusts it. The rest are older acquaintances: this crew was hiding OtterCookie inside SVG files aimed at developers in July.
What leaves the machine is not only wallet keys and seed phrases. The advisory lists browser-stored credentials, clipboard contents, keystroke logs, screenshots, and photographs of driver's licenses and passports, which North Korean IT workers reuse to impersonate victims and win contract work of their own.
Japan pulled apart its first laptop farm
For the first time in Japan, investigators identified and dismantled a laptop farm, the arrangement where an enabler keeps employer-issued computers at home for operators to drive remotely from North Korea, China or Russia. Japanese authorities found evidence of several hundred million yen in cryptocurrency leaving the country that way.
The advisory is blunt that paying these workers may breach domestic law and DPRK sanctions, and it records two cases where revenue generation turned destructive: one worker extorted an employer over payment and published its proprietary source code, and another, hired to maintain a website, defaced it and rendered it inaccessible.
The tells that saved the exchange
Interviewers in the advisory's cases kept noticing the same things: excuses to avoid meeting in person, requests to be paid in cryptocurrency, eyes flicking to a second monitor as if reading, other voices in the background, and video or audio that froze repeatedly. Check Point Research's weekly bulletin picked the advisory up on 21 September. For anyone hiring remote engineers, the cheapest control in the document is the one that exchange used: ask a candidate to explain their own resume.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.