A joint advisory published by the FBI, Japan’s National Police Agency (NPA), Australia’s Cyber Security Centre, and Germany’s Federal Office for the Protection of the Constitution on 18 September 2026 has laid bare one of the most damaging and operationally creative North Korean cyber campaigns ever documented. The group, tracked as WaterPlum (also known as Contagious Interview), has infected more than 30,000 developer and IT professional devices across over 100 countries, stolen credentials from more than 7,000 cryptocurrency wallets, and funnelled at least $10.71 million in cryptocurrency back to Pyongyang — all by exploiting the one thing every IT professional does regularly: participate in job interviews.

The scale of what this advisory reveals should alarm every CTO, CISO, and hiring manager in India’s booming IT sector. When a developer sits down for what they believe is a legitimate technical interview and runs a “coding assignment,” they are potentially handing a state-sponsored threat actor the keys to their employer’s cloud environment, source code repositories, and client networks.

Key Takeaways

  • WaterPlum / Contagious Interview is a DPRK-linked threat actor under the 313 General Bureau, responsible for weapons research funding.
  • The campaign ran from at least December 2025 through July 2026, hitting 30,000+ devices in 100+ countries.
  • Attack vector: fake recruiter outreach on LinkedIn, freelance platforms, and GitHub — followed by a “coding test” that installs malware.
  • Malware families deployed: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle — a full access-persistence-exfiltration stack.
  • Attackers use AI-generated face-swapping during live video interviews to maintain cover.
  • From one compromised developer laptop, WaterPlum pivots to the employer’s AWS environment, GitHub org, and client infrastructure.
  • India, with its 5.8 million software developers and deep crypto-startup ecosystem, is an extremely high-value target environment.

What Is WaterPlum? Background on a State-Sponsored Cyber Heist Machine

WaterPlum is a North Korean state-sponsored threat actor assessed by US and allied intelligence to operate under the 313 General Bureau, the Munitions Industry Department unit responsible for the DPRK’s weapons research and production. In plain terms: the hackers who steal crypto from developers in Bengaluru and Noida are partly funding Pyongyang’s ballistic missile programme.

The campaign known as “Contagious Interview” has been tracked since at least 2023, but the September 2026 advisory marks the first time a coordinated multi-nation law enforcement and intelligence coalition has publicly named, scoped, and attributed the operation at this level of detail. The advisory was co-signed by the FBI, Japan’s NPA and National Cybersecurity Office, Australia’s ASD-ACSC, Germany’s BfV and BND, and the US Department of Defense Cyber Crime Center (DC3).

How the Attack Works: From LinkedIn Message to Root Access

The WaterPlum attack chain is deceptively simple and relies almost entirely on social engineering — which is exactly why traditional perimeter defences do nothing to stop it.

Stage 1 — Initial Contact. WaterPlum operators create convincing profiles on LinkedIn, GitHub, Upwork, Freelancer, and crypto-focused job boards, posing as venture capitalists, senior engineers at reputable tech firms, or talent acquisition specialists. The targets are typically blockchain developers, React/Node.js engineers, AI/ML practitioners, and cryptocurrency professionals — all high-income segments that are actively being recruited in the current market.

Stage 2 — The Interview Funnel. The target is invited to a technical interview. Sometimes this takes weeks of rapport-building. The adversary demonstrates knowledge of current market rates, real company structures, and real technical stacks. During video calls, FBI investigators found that WaterPlum operators use AI face-swapping software to present a believable human face, and when the deepfake glitches, they claim network problems and turn off their cameras.

Stage 3 — The Poisoned Assignment. The candidate is asked to clone a GitHub repository or install an npm package to complete a “coding challenge” or “debug a video conferencing issue.” The package is malicious. Once executed, the installer drops one or more of five active malware families.

Stage 4 — Compromise and Pivot. Once inside the developer’s machine, the operators harvest browser credentials, SSH keys, cloud credentials (AWS, GCP, Azure), cryptocurrency wallet seed phrases, and access tokens. They then pivot laterally into the developer’s employer network, CI/CD pipelines, cloud environments, and any client systems the developer has access to. The compromise of one freelance developer can cascade into multiple victim organisations.

The Technical Malware Stack: BeaverTail, InvisibleFerret, and Three More

What distinguishes WaterPlum from opportunistic cybercriminals is the sophistication and modularity of their malware toolkit. The five known families form an interlocking capability stack:

Malware Family Language / Platform Primary Capability
BeaverTail JavaScript / npm Initial access dropper; concealed in malicious npm packages
InvisibleFerret Python Full-featured backdoor; remote command execution, screen capture
OtterCookie Multi-platform Combined RAT + infostealer; credential and wallet exfiltration
OtterCandy Multi-platform Persistence; scheduled task / cron-based re-infection
StoatWaffle Multi-platform Lateral movement; tunnelling into internal networks

BeaverTail is typically the first stage, delivered via a package.json in an npm package or a poisoned VSCode project. Once the candidate runs npm install or npm start, the payload executes with whatever privileges the developer’s terminal has — which, on a personal laptop, is often equivalent to full user context with access to all stored credentials.

InvisibleFerret, the Python-based backdoor, is the workhorse for sustained access. It communicates with C2 infrastructure over HTTPS and can receive arbitrary shell commands, exfiltrate files, and capture screenshots. Investigators note that C2 domains regularly rotate and are hosted on cloud infrastructure to blend with legitimate traffic — a technique that bypasses many signature-based detection systems.

The India Angle: Why Your Developer Pipeline Is a High-Value Target

India deserves a specific mention here. With over 5.8 million software developers — the second largest developer population in the world — and a rapidly growing Web3 and cryptocurrency ecosystem, India presents an enormous attack surface for WaterPlum. Several factors compound the risk:

  • High freelance activity: India has one of the largest pools of freelance developers on Upwork, Freelancer, Fiverr, and Toptal — platforms that WaterPlum operators specifically target.
  • Active crypto market: India’s retail cryptocurrency participation has grown despite regulatory uncertainty. Developers with crypto wallet access are prime targets.
  • Employment market pressures: Job insecurity in the post-layoff tech market makes candidates more willing to engage with unsolicited interview opportunities, including from unknown firms.
  • Weak endpoint hygiene in SMBs: Many small and mid-size Indian software companies lack endpoint detection and response (EDR) tools on developer machines, making post-compromise detection slow.

India’s CERT-In compliance requirements mandate incident reporting for breaches, but most WaterPlum infections go unreported because the victim organisations never realise their developer’s laptop was compromised in the first place.

What You Should Do: Sanjay Seth’s Defensive Playbook

This threat cannot be addressed by a firewall rule or a SIEM signature alone. It demands a combination of policy, technical controls, and human awareness. Here is a prioritised response framework:

  1. Brief every developer and technical recruiter immediately. Share the FBI/NPA advisory with your engineering leadership today. Every developer should know that an unsolicited coding assignment — especially one involving npm packages or VSCode extensions — is a red flag, regardless of how professional the recruiter appears. Confirm recruiter identities via the official company website before executing any code.
  2. Sandbox all coding assignments. Establish a policy that no interview-related code is ever executed on a production or company-networked device. Provide disposable virtual machines (VMs) or ephemeral containers for this purpose. A coding assessment that requires installation of npm packages should immediately trigger suspicion.
  3. Audit and restrict npm, pip, and cargo execution on developer endpoints. Implement application control policies that flag or block execution of newly installed packages before a security scan. Tools like Socket.dev, Snyk, or OSSGadget can detect known-malicious npm packages before installation completes.
  4. Enforce zero-trust principles on developer workstations. A zero-trust architecture that segments developer machines from production cloud credentials and internal tooling limits the blast radius of any compromise. If a developer’s laptop is infected, the attacker should not be able to pivot into AWS or GitHub from that machine without triggering MFA and anomaly detection.
  5. Rotate cloud credentials and SSH keys for high-risk roles. Any developer who has recently participated in online interviews with unknown organisations should be considered potentially compromised. Rotate their AWS IAM credentials, revoke and reissue SSH keys, and audit their recent git activity and cloud API calls.
  6. Deploy EDR on all developer endpoints. Endpoint detection and response tools (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint) with behavioural analysis can detect BeaverTail’s post-install behaviour — specifically the spawning of Python processes from within a node execution context — even without a known signature.
  7. Monitor for anomalous npm installs via SIEM. Alert on npm package installations that spawn child processes, make outbound HTTPS connections to new external IPs, or write to startup/persistence locations (e.g., crontab, systemd, or Windows Task Scheduler entries created immediately after a package install).

For organisations running Fortinet’s Security Fabric, FortiEDR’s in-memory protection module is specifically equipped to detect scripting-language-based stagers like BeaverTail. FortiAnalyzer can correlate these endpoint events with network telemetry, flagging unusual C2 beaconing patterns that would otherwise go unnoticed in a busy developer-team environment.

Official Sources and Advisory Links

The following authoritative sources were used to verify every fact in this article. Security teams should review the full advisory documents:

Frequently Asked Questions

How do I know if I was targeted by WaterPlum?

If you have received unsolicited interview requests from unfamiliar companies — especially from well-presented LinkedIn profiles representing AI, cryptocurrency, or NFT companies — and were asked to run, install, or execute code as part of the process, you may have been targeted. Signs of actual compromise include unexpected Python processes, unexplained cron jobs or scheduled tasks, and unusual outbound HTTPS connections to newly registered domains. Run a full EDR scan and review your SSH known_hosts, git credentials, and cloud API key last-used timestamps.

Are Indian companies specifically targeted?

The advisory does not name India specifically, but with the world’s second-largest developer workforce and a high density of freelance contractors on platforms WaterPlum is known to use, Indian IT professionals are statistically among the most exposed. The FBI advisory notes that targets span “over 100 countries,” and APAC — including India — has been a focus of North Korean financially motivated cyber operations for several years.

Does this affect companies that don’t use cryptocurrency?

Yes. Cryptocurrency theft is the financial goal, but the campaign’s secondary damage is corporate espionage and lateral access. A blockchain developer who runs a malicious package on their personal laptop may also be authenticated to their employer’s GitHub, internal Jira, Confluence, AWS, or Azure tenant. WaterPlum operators harvest those credentials regardless of whether the employer operates in crypto. Sensitive client data, IP, and internal tooling are all at risk.

What is the quickest action I can take right now?

Three immediate steps: (1) Send a security awareness email to all developers and technical staff linking to this story and the FBI advisory. (2) Check your endpoint management platform for any recently installed npm/Python packages on developer machines that were not part of a managed deployment. (3) Review cloud IAM access logs for any developer accounts that have made unusual API calls in the past 90 days, particularly those involving new role assumptions, S3 bucket enumeration, or secret store access.


Is Your Organisation Exposed?

WaterPlum is one of dozens of active nation-state threats targeting Indian enterprises right now. If your organisation employs remote developers, uses freelance contractors, or operates in the cryptocurrency or fintech space, a developer endpoint security and zero-trust architecture review is not optional — it is urgent.

Sanjay Seth has spent over 30 years designing and defending enterprise networks across India, with deep expertise in endpoint security, network segmentation, and zero-trust implementations using Fortinet’s Security Fabric. Book a free 30-minute security assessment to identify where your developer pipeline and network segmentation may be leaving you exposed.