WaterPlum

Brand Protection Software: WaterPlum’s 30,000-Device Campaign

Brand protection software is not a substitute for endpoint security, but it can provide another layer of visibility when threat actors use trusted identities, recruiting platforms, and online infrastructure to reach victims. The latest WaterPlum campaign shows why that broader view matters. A joint advisory from authorities in Japan, the United States, Australia, and Germany says the North Korean-linked group infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.

The campaign, also known as “Contagious Interview,” targeted software developers, engineers, web professionals, and people working with cryptocurrency, blockchain, and Web3 technologies. Rather than relying on a conventional phishing email alone, WaterPlum used fake employment opportunities and technical interviews to persuade targets to download malicious files or execute code.

For security teams, the incident is a useful reminder that the attack surface now includes the places where employees search for work, communicate with recruiters, download development projects, and interact with unfamiliar digital infrastructure.

What Happened in the WaterPlum Campaign?

According to the joint government advisory, WaterPlum actors posed as prospective employers and sometimes impersonated legitimate artificial intelligence, cryptocurrency, or NFT companies. They also used recruiting, freelance, social-media, and gig-work platforms to reach potential victims.

During the recruitment process, targets were asked to participate in online interviews or complete coding assignments. In some cases, victims were instructed to download projects or troubleshoot supposed video-conferencing problems.

The downloaded material could contain malicious npm packages carrying malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. Once access was established, the actors could use remote-access tools and information stealers to collect credentials, cryptocurrency wallet information, browser data, clipboard contents, keystrokes, screenshots, and files.

The Australian Cyber Security Centre and its international partners report that more than 7,000 cryptocurrency wallets had funds or credentials exfiltrated and that approximately 1.7 billion Japanese yen, equivalent to $10.71 million, in cryptocurrency was transferred to North Korea.

The figures come from the joint law-enforcement assessment and should be understood in that context. They describe activity attributed to WaterPlum between December 2025 and July 2026, rather than evidence that every infected device belonged to an organization that was subsequently compromised.

Why WaterPlum’s Recruitment Strategy Matters

The unusual part of the campaign is not simply the malware. It is the trust relationship used to deliver it.

A person applying for a software-development job may reasonably expect to download a coding assignment, open a repository, install dependencies, or troubleshoot a development environment. Attackers exploited that expectation by presenting malicious activity as part of a legitimate recruitment workflow.

The advisory says WaterPlum has also used online collaboration platforms and code repositories to host malicious packages. This means the initial warning sign may not be an obviously suspicious website or email address. It could instead be an unexpected software project, unusual package, unfamiliar recruiter account, or request to troubleshoot a supposed technical problem.

For organizations, this creates a security problem that crosses several teams:

  • HR and recruitment teams may encounter fraudulent candidates or recruiters.
  • Developers may receive malicious coding assignments.
  • SOC teams may see endpoint or identity indicators after execution.
  • Fraud teams may encounter stolen identity or cryptocurrency information.
  • Threat-intelligence teams may need to correlate external infrastructure.
  • Brand protection teams may need to investigate impersonated company identities.

This is also where a broader compromised data search can become useful after an incident. Finding exposed credentials or identity information does not establish how it was stolen, but it can provide an additional signal for an investigation when correlated with endpoint, identity, and threat-intelligence evidence.

How WaterPlum Can Turn a Job Application Into an Enterprise Risk

The government advisory warns that successful infections can create opportunities for further intrusion into organizations that employ targeted developers. Stolen credentials may potentially be used to access employer, client, or contracting-party systems, while stolen sensitive information can support additional theft or extortion.

That makes the attack chain broader than an individual malware infection.

A simplified defensive view looks like this:

  1. A threat actor presents a fraudulent employment opportunity.
  2. A developer enters a recruitment or interview process.
  3. The target receives a coding assignment or technical troubleshooting request.
  4. Malicious software or packages are executed.
  5. Credentials, wallet information, and other sensitive data may be collected.
  6. Stolen access can create opportunities for further abuse against connected organizations.

The key lesson is that the employee’s personal device can become relevant to corporate security even before that person officially joins an organization.

For companies hiring developers or contractors, identity verification and access controls therefore need to extend beyond the recruitment decision itself.

Where Brand Protection Software Fits

WaterPlum is primarily a malware and social-engineering story, not a conventional lookalike-domain campaign. That distinction matters.

However, the campaign demonstrates why organizations should monitor how their brands, products, recruiters, and corporate identities are represented externally. Threat actors can impersonate legitimate companies during recruitment, use trusted company names to establish credibility, or create fraudulent online identities around real organizations.

This is where brand protection software can complement endpoint and identity controls.

SpoofGuard describes its platform as providing domain threat intelligence and brand protection, including discovery of lookalike domains, monitoring of newly registered domains, DNS and certificate signals, website analysis, phishing-related intelligence, and risk scoring.

The important point is not to classify every similar domain as malicious. A domain that resembles a company’s name may be harmless, parked, inactive, or legitimately registered. Analysts should combine domain similarity with website content, infrastructure, registration activity, phishing indicators, and other evidence before determining whether active abuse is occurring.

Why Domain Monitoring Software Still Matters

Domain monitoring software can help organizations investigate the external infrastructure surrounding a brand, even when the original attack did not begin with a malicious domain.

For example, security teams can monitor for:

  • Newly registered domains containing corporate or product names
  • Typosquatting and homoglyph variations
  • Fraudulent recruitment or careers websites
  • Fake developer-support portals
  • Unauthorized use of corporate logos
  • Suspicious login or credential-collection pages
  • DNS and certificate changes associated with suspicious domains
  • Domains appearing in phishing or threat-intelligence feeds

SpoofGuard’s published technology information describes monitoring across domain registrations, DNS and infrastructure signals, SSL and Certificate Transparency data, website content, and phishing intelligence.

Review SpoofGuard’s domain monitoring technology

This type of external visibility can complement EDR, SIEM, MFA, secure email gateways, identity security, vulnerability management, and incident response. It does not replace those controls.

What Security Teams Should Investigate

Organizations hiring developers, contractors, or technical freelancers can use the WaterPlum advisory as a reason to review their recruitment and third-party access processes.

Security teams should consider:

  • Reviewing whether developers received unexpected coding projects or software packages.
  • Checking endpoint telemetry for suspicious execution associated with downloaded projects.
  • Investigating unusual authentication activity from developer accounts.
  • Reviewing browser-stored credentials and other secrets on potentially affected systems.
  • Rotating credentials where exposure is suspected.
  • Reviewing access to source-code repositories, cloud systems, package registries, and CI/CD environments.
  • Restricting developer access according to least-privilege principles.
  • Monitoring external infrastructure for impersonation of corporate brands or recruitment services.
  • Preserving relevant evidence before rebuilding or resetting affected systems.

The advisory specifically recommends EDR for companies and emphasizes limiting source-code, credential, and system access to the minimum necessary.

The Australian advisory also recommends caution when developers are asked to execute untrusted code and provides guidance for organizations investigating potential WaterPlum activity.

 

Spoofing Detection Needs Context

WaterPlum’s use of fake employment identities also highlights an important distinction in external threat intelligence: impersonation is not automatically proof of compromise.

A company can be impersonated without its infrastructure being breached. A lookalike domain can exist without hosting malicious content. A fake recruiter can misuse a company’s name without having access to the legitimate company’s systems.

Effective spoofing detection therefore needs context.

Security analysts should separate:

  • Brand similarity from confirmed impersonation
  • Impersonation from phishing
  • Phishing from malware delivery
  • Suspicious infrastructure from confirmed malicious infrastructure
  • External brand abuse from an internal organizational compromise

This approach reduces false positives while giving SOC, fraud, and brand protection teams better evidence for escalation.

SpoofGuard’s recent research on fake coding-test campaigns similarly emphasizes the relationship between phishing detection, recruitment-themed social engineering, and external domain intelligence.

What Organizations Can Learn From WaterPlum

The biggest takeaway is that recruitment has become part of the security boundary.

Security awareness programs often focus on suspicious emails, malicious attachments, and fake login pages. Those remain relevant, but technical employees may face a different type of social engineering: an apparently legitimate professional opportunity that requires them to download software or execute code.

Organizations can reduce exposure by combining recruitment controls with technical safeguards. Developers should have clear procedures for handling untrusted projects, while security teams should monitor endpoints, identities, repositories, and cloud environments for signs of abuse.

External monitoring adds another layer by looking beyond company-owned systems. It can help identify domains, websites, and infrastructure that may be abusing a company’s identity, particularly when attackers use recognizable brands to make fraudulent activity appear credible.

Frequently Asked Questions

What is WaterPlum?

WaterPlum is the name used by Japanese, U.S., Australian, and German authorities for a North Korean cyber actor group also referred to as “Contagious Interview.” Authorities say it targeted IT professionals through fraudulent employment opportunities and infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.

How did WaterPlum target job seekers?

WaterPlum actors posed as prospective employers and used recruiting, freelance, social-media, and gig-work platforms. Targets could be asked to complete coding assignments or troubleshoot supposed technical problems. Authorities say malicious npm packages and other files were used to deliver malware during these interactions.

Does WaterPlum mean a company has been breached?

Not necessarily. Infection of an individual device does not automatically establish that the person’s employer was compromised. However, stolen credentials or persistent access from a developer’s device could create additional organizational risk, particularly where that device has access to corporate repositories, cloud services, credentials, or sensitive information.

Can brand protection software prevent WaterPlum attacks?

Brand protection software cannot prevent every malware or recruitment-based attack. Its role is different: it can provide external visibility into suspicious domains, phishing infrastructure, brand impersonation, and related digital abuse. Those signals should complement endpoint, identity, email, network, and incident-response controls.

Strengthen Visibility Into External Brand Abuse

WaterPlum demonstrates how a trusted company identity can become part of a social-engineering attack without requiring the victim organization itself to be compromised. Security teams can use external domain intelligence alongside endpoint and identity telemetry to investigate suspicious infrastructure, impersonation, and phishing activity.

Organizations evaluating this layer of defense can review SpoofGuard’s monitoring capabilities or test its 7-day free trial to examine their external domain exposure and brand-protection workflow.

Start a 7-day SpoofGuard free trial

Disclaimer: Spoofguard reports on publicly available threat-intelligence sources. Inclusion of an organization in an article does not imply confirmed compromise. All claims are attributed to external sources unless explicitly verified.