Insights Crypto WaterPlum fake job offer malware: How to spot and avoid it
post

Crypto

23 Sep 2026

Read 13 min

WaterPlum fake job offer malware: How to spot and avoid it *

WaterPlum fake job offer malware targets developers, learn checks to spot it and secure your accounts.

North Korean-linked hackers are luring developers and IT workers with “dream jobs,” then slipping malware onto their devices. The WaterPlum fake job offer malware spreads through social media and job sites, steals logins and crypto, and gives attackers backdoor access. Learn the red flags, safe interview habits, and steps to protect your money and data. International cyber agencies warn that a North Korean group called WaterPlum, also known as Contagious Interview, has infected tens of thousands of devices in more than 100 countries. The attacks ran from late 2025 into mid-2026 and are still active. The group has taken credentials or funds from more than 7,000 crypto wallets, moving about $10.8 million to accounts tied to the regime. WaterPlum often impersonates AI, crypto, or NFT firms, and even uses real recruiting services to look credible. Targets are mostly software developers and IT professionals in Japan, the United States, Europe, and other regions. During interviews or test assignments, victims are told to download files that secretly install backdoors. From there, attackers can steal data, drain wallets, and move inside company networks. Authorities in the US and Japan say they have identified “enablers” who help the operation.

What is the WaterPlum operation?

WaterPlum is a state-backed cyber group that pretends to be a legitimate employer. It reaches out to candidates on LinkedIn, Telegram, email, and job boards. The team posts high-paying remote roles, often for AI or blockchain work. It then invites candidates to quick interviews and “simple” take-home tests. The tests look normal, but they hide malicious code. This campaign is not a random scam. It is a planned way to place malware on devices that belong to skilled workers. Attackers seek GitHub, cloud, and VPN credentials. They also look for crypto wallet secrets. They use that access to steal money and to move into company systems. In short, the WaterPlum fake job offer malware is a professional lure built to trick careful, technical people.

How the scheme works, step by step

1) The initial approach

Attackers contact you with a job that matches your skills. The message sounds urgent and flattering. The recruiter may use a real company name, a cloned website, or a profile with stolen photos. They may ask to switch the chat to WhatsApp or Telegram right away.

2) The interview and assignment

You get a short call that feels real. The interviewer shares a “coding exercise” or “skills test.” You must download a file to run it on your machine. They may say the file is safe, private, or time-locked. Sometimes they share a password-protected archive to bypass email security.

3) Infection and theft

The file plants a backdoor. The malware starts to log keys, take screenshots, and harvest browser cookies and tokens. It may try to disable antivirus tools. If you hold crypto, it may watch clipboards or prompt you to unlock a wallet. Later, the attackers use the backdoor to move deeper into your work tools, cloud accounts, or company network.

Red flags you can spot fast

  • High pay and urgent deadlines with a vague job description
  • Recruiter pushes you to move off a trusted job platform to a private app
  • Interview link, email domain, or calendar invite does not match the company website
  • You are asked to run an .exe, .msi, .pkg, .dmg, or macro-enabled document
  • Assignment needs admin rights or full disk access to “work”
  • Company refuses a live coding screen share and insists you run their binary
  • No company employee can be found on LinkedIn or the names do not match
  • They request your ID images, bank info, or crypto seed phrase early in the process
  • They impersonate well-known AI/crypto/NFT brands but the site is a recent clone
  • How to spot and avoid the WaterPlum fake job offer malware

    Verify the employer

  • Check that the recruiter’s email domain matches the official site
  • Look up employees on LinkedIn and confirm their roles and tenure
  • Call the company’s main phone number to confirm the job and recruiter
  • Control the test environment

  • Refuse to run unknown executables or scripts on your main device
  • Use a throwaway laptop, a fresh virtual machine, or a cloud dev environment
  • Never grant admin rights for a test; ask for a browser-based or GitHub-hosted task
  • Scan before you run

  • Upload files to a multi-engine scanner before opening
  • Check file signatures and hashes; be wary of password-protected archives
  • Do not enable Office macros or bypass security prompts
  • Keep the chat in safe channels

  • Stay inside the job platform until you confirm the employer
  • Avoid Telegram/WhatsApp links until you trust the contact
  • Ask for a company email follow-up and a calendar invite from the firm’s domain
  • Protect your crypto and accounts

  • Use a hardware wallet for long-term funds; never share your seed phrase or private keys
  • Keep a separate “hot” wallet with small balances for testing or dApps
  • Enable phishing-resistant 2FA (e.g., security keys) on email, GitHub, cloud, and exchanges
  • Use a password manager and unique passwords for every service
  • Regularly review and revoke dApp token approvals and connected apps
  • Update your OS, browser, and security tools; turn on automatic updates
  • If you clicked or ran a file

  • Disconnect from the internet; note the time of the incident
  • From a clean device, change passwords for email, GitHub, cloud, and crypto exchanges
  • Move crypto to a new wallet with a new seed phrase using a safe device
  • Review wallet approvals and revoke risky permissions
  • Scan the suspect device with reputable antivirus/EDR; consider a full OS reinstall
  • Alert your employer if you used any work accounts or assets
  • Report to law enforcement such as the FBI’s IC3 or your national cybercrime unit; in Japan, contact the NPA
  • Who is most at risk right now?

  • Software developers, DevOps engineers, and SREs
  • IT admins with access to VPNs, cloud consoles, and identity tools
  • Crypto traders, founders, and anyone who manages project wallets
  • Freelancers and remote job seekers contacted via social media
  • Candidates in Japan, the United States, and Europe, where activity is high
  • How companies and recruiters can reduce exposure

  • Publish a clear hiring playbook: no executables, no macros, no off-platform tests
  • Host all exercises on the company’s GitHub or a trusted browser-based IDE
  • Require recruiters to use company email and verified scheduling tools
  • Train hiring teams to spot impersonation and to verify candidate identities securely
  • Set up brand monitoring and DMARC/DKIM/SPF to fight spoofed domains
  • Block risky file types at the email gateway and enforce strong endpoint protection
  • Log and review recruiter-candidate file exchanges; keep a short list of allowed platforms
  • Why this threat keeps working

    Attackers understand pressure. They use speed, praise, and time-limited offers to bypass caution. Many job seekers feel they must agree to odd requests to stay in the running. Some tests look polished and include real code. That is why the simplest rules help: do not run unknown files, verify domains, and keep work in safe environments. If a team will not respect those boundaries, step away.

    What the data shows

    Authorities from Australia, Germany, Japan, and the United States report that the campaign ran from December 2025 to July 2026, and it is not over. More than 7,000 wallets were hit, and at least $10.8 million moved to accounts tied to North Korea. Investigators say there are “enablers” in multiple countries who help with payments and cover. This is a global issue, not a single platform glitch. Job hunting should be exciting, not risky. Treat every unexpected offer with care. Verify the sender, control the test environment, and never run untrusted files on a device that holds keys or work credentials. By following these simple steps, you can spot, block, and report the WaterPlum fake job offer malware before it hurts you or your team. (Source: https://www.the-independent.com/tech/security/north-korea-hackers-waterplum-crypto-b3054513.html) For more news: Click Here

    FAQ

    Q: What is the WaterPlum fake job offer malware? A: WaterPlum fake job offer malware is a campaign run by a North Korea-linked group known as WaterPlum or Contagious Interview that poses as legitimate employers to trick software developers and IT professionals. During interviews or coding tests they ask candidates to run files that install backdoors to steal credentials and cryptocurrency. Q: How do attackers reach and lure candidates in this campaign? A: They contact targets via LinkedIn, Telegram, email, and job boards, often impersonating AI, cryptocurrency, or NFT companies or using real recruiting services. Messages advertise high-paying remote roles and push candidates into quick interviews or take-home tests that require downloading files. Q: What red flags should job seekers watch for in suspicious offers? A: Red flags include vague job descriptions with unusually high pay, recruiters pushing you off trusted platforms, mismatched email domains or calendar invites, and requests to run executables or grant admin rights for tests. Early demands for ID images, bank details, or crypto seed phrases are also warning signs. Q: How can I safely complete a coding test without risking infection? A: Refuse to run unknown executables or scripts on your main device and request a browser-based or GitHub-hosted task instead. If you must run code locally, use a throwaway laptop, a fresh virtual machine, or a cloud development environment and never grant admin rights. Q: I ran a suspicious file—what immediate steps should I take? A: Disconnect the affected device from the internet and note the time of the incident, then from a clean device change passwords for email, GitHub, cloud accounts, and crypto exchanges. Move crypto to a new wallet with a new seed phrase using a safe device, scan the suspect machine with reputable antivirus or EDR, consider a full OS reinstall, and report the incident to law enforcement such as the FBI’s IC3 or your national cybercrime unit. Q: Who is most at risk from the WaterPlum fake job offer malware? A: Software developers, DevOps engineers, SREs, IT administrators with access to VPNs or cloud consoles, and crypto traders or project founders are the primary targets. Freelancers and remote job seekers contacted via social media are also at heightened risk, especially in Japan, the United States, and Europe where activity has been high. Q: How widespread was the campaign and what was stolen? A: Authorities say the campaign infected tens of thousands of devices across more than 100 countries between December 2025 and July 2026 and that the threat remains active. Investigators found credentials or funds taken from over 7,000 crypto wallets, with about $10.8 million moved to accounts tied to North Korea. Q: What can hiring teams do to reduce exposure to this threat? A: Companies should publish clear hiring rules such as no executables, no macros, and no off-platform tests, host exercises on the company’s GitHub or trusted browser-based IDEs, and require recruiters to use verified company email and scheduling tools. They should also train hiring teams to spot impersonation, implement DMARC/DKIM/SPF and brand monitoring, block risky file types at the email gateway, and enforce strong endpoint protection.

    * The information provided on this website is based solely on my personal experience, research and technical knowledge. This content should not be construed as investment advice or a recommendation. Any investment decision must be made on the basis of your own independent judgement.

    Contents