WaterPlum turns a normal developer interview into an endpoint-security decision. A joint advisory from agencies in Japan, the United States, Australia and Germany says the North Korea-linked operation compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026. Authorities say the actors accessed funds or credentials from more than 7,000 cryptocurrency wallets and transferred about ¥1.7 billion, equivalent to $10.71 million, to North Korea.

How WaterPlum crosses the hiring boundary

The campaign does not need a software vulnerability to begin. The attacker creates a credible recruiting conversation, moves the target into a video interview and asks the candidate to open a project, install a dependency or fix a supposed conferencing problem. Those actions are normal enough in technical hiring that the victim may execute them on a personal computer containing browser sessions, source-code credentials and cryptocurrency wallets.

The joint advisory associates the operation with malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. BleepingComputer and The Register independently describe the same mechanism and scale, while NEXSIGHT separately summarises the multinational warning. The attribution and victim figures remain agency assessments; this article does not convert them into independently observed facts.

WaterPlum attack pathA recruiter approach leads to a poisoned coding task and then credential and wallet theft.Fake recruiterFake recruiterBCoding testCoding testBDevice accessDevice accessB
The hiring process is the delivery mechanism; isolation must begin before code execution.

The device count understates the business risk

A compromised personal laptop can become more than an individual loss. Developers often use password managers, Git credentials, package registries, cloud consoles and collaboration tools on the same device. If the victim later connects to an employer or client environment, stolen credentials or persistent malware may create a second route into corporate systems.

The wallet total attracts attention, but identity documents and session tokens can have longer value. Authorities warn that stolen identities can support fraudulent remote-worker applications. That creates a reinforcing cycle: a fake recruiter steals credentials and documents, then another operator may reuse the identity to obtain trusted access elsewhere.

The campaign also exploits ownership gaps. Recruiting teams manage the interview, candidates control their devices, engineering teams design tests and security teams respond only after an alert. No one function sees the complete chain. Treating the coding task as an executable supplier artifact gives companies a clearer control point.

Isolation should be the default

Employers can remove much of the risk by providing a browser-based sandbox or disposable virtual environment for every exercise. Candidates should not need to clone an unknown repository, run package-manager install commands or change security settings on a personal machine. The environment should block outbound secrets, expire after the session and record the exact files supplied.

Candidates can apply the same principle independently. Verify the company through its official domain, contact a known employee using a separate channel and refuse instructions that disable security controls. Run unavoidable code in a new virtual machine with no mounted home directory, browser profile, SSH keys or wallet software. A sandbox reduces exposure; it does not prove the recruiter is legitimate.

Package controls matter because several WaterPlum tools arrive through developer ecosystems. Organisations should use lockfiles, private registries, dependency review and behavioural monitoring, but those controls cannot compensate for giving an unknown project broad local access. The first question is whether the code must run at all, and the second is where it can run safely.

Hiring and security teams need one playbook

A practical workflow begins with approved recruiting domains and named scheduling platforms. Interviewers should never ask candidates to install remote-access software or copy commands from chat without prior notice. Security teams should publish a route for candidates to verify unusual requests, and recruiters should know how to escalate impersonation reports.

When an exposure is suspected, disconnect the device, preserve evidence and rotate credentials from a clean system. Wallet users should move assets using a separate trusted device and assume exposed seed phrases are permanently compromised. Employers should review cloud tokens, source-code access and recent session activity rather than limiting the investigation to the interview application.

This boundary problem resembles emerging attacks on AI-enabled browsers, where trusted software becomes an action channel. Our report on BragJack browser-agent hijacking explains why extension trust needs scrutiny. Active exploitation also rewards rapid response; see the Orkes Conductor vulnerability analysis.

What the advisory changes

The new disclosure supplies a multinational, quantified baseline for a campaign that security researchers have tracked under other names. It connects recruiting lures, malware delivery, wallet theft, identity abuse and fraudulent IT work into one operating model. That broader view matters because individual alerts can otherwise look like unrelated candidate fraud or commodity malware.

Metrics should change accordingly. Companies can track how many technical exercises run in controlled environments, how often recruiters use unapproved channels, how quickly suspicious domains are verified and whether candidate reports reach security teams. These measures test the process that attackers exploit, not only the malware that appears at the end.

Vendors should also distinguish confirmed indicators from broad suspicion. International applicants and remote developers are not inherently risky. Controls should focus on verifiable behaviour: domain ownership, identity consistency, repository provenance, requests to bypass safeguards and unexpected outbound connections. That protects candidates while making the attack harder.

The central lesson

WaterPlum succeeds because code execution is wrapped in social permission. The victim believes the project is part of an opportunity, so the usual warning signs feel like steps toward a job. Security awareness that says “do not open suspicious files” is too abstract when the file arrives from a convincing interviewer.

The stronger rule is operational: no hiring test gets trust from context alone. Put every project in a disposable environment, verify every recruiter out of band and keep personal credentials away from the exercise. The joint advisory’s numbers show that this is not an edge case. For developer-heavy organisations, the interview pipeline is now part of the attack surface.

Frequently asked questions

What is WaterPlum?

WaterPlum is the name used in the joint government advisory for North Korea-linked actors associated with fake recruitment and malicious developer tasks.

Did WaterPlum exploit one specific software flaw?

The described initial access relies on social engineering and execution of poisoned projects or commands, not one named vulnerability. Individual malware components may use additional techniques after execution.

What should a candidate do after running a suspicious test?

Disconnect the device, preserve evidence, contact relevant employers or platforms, and rotate credentials from a separate clean system. Treat exposed wallet seed material as permanently compromised.

WaterPlum confirmed campaign scaleAuthorities report at least 30,000 devices in more than 100 countries, more than 7,000 cryptocurrency wallets and 10.71 million US dollars transferred.30,000+devices100+ countries7,000+walletsfunds or credentials$10.71mtransferredagency estimateDecember 2025–July 2026, according to the joint advisory
All figures are attributed to the multinational government advisory and describe its confirmed assessment window.

Sources

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.