This week, Sherri and Matt dig into a joint advisory from seven government agencies across Japan, the US, Australia, and Germany naming WaterPlum, the North Korean actors posing as prospective employers to target software developers and IT professionals. Japan’s National Police Agency reports at least 30,000 infected devices in more than 100 countries between December 2025 and July 2026, with funds or credentials taken from more than 7,000 cryptocurrency wallets and roughly $10.71 million moved to North Korea. Sherri and Matt break down how the lure works, why coding challenges are such an effective delivery mechanism, and what changed with the newest malware family, StoatWaffle, which can execute when a trusted folder is opened in VS Code. They connect it to the case LMG’s Tom Pohl analyzed in June and examine how North Korea is now working both sides of the hiring table, as both interviewer and applicant. Key Takeaways: Make onboarding a security checkpoint. Identity verification should be an HR and IT project. Verify every new hire’s identity, issue fresh credentials, and monitor accounts closely during the first few weeks. A compromised candidate can bring an existing infection into your organization on day one. Because the same operation also uses fake applicants, verify claimed locations, IP addresses, and résumé skills. Treat password reuse as a policy issue, not a question. The malware Tom analyzed harvested saved credentials from ten different browsers. Require unique corporate passwords, audit them against known-breach lists, and use phishing-resistant MFA. Anyone with source code or administrative access should be considered for hardware-based authentication such as a YubiKey. Keep developers off personal devices. Personal laptops often combine job hunting, coding challenges, credentials, and crypto wallets. In one case Tom analyzed, the person infected wasn't even the primary laptop user. Require company-managed devices for anyone accessing code, cloud infrastructure, or production systems. If personal-device use is allowed, document it as an accepted risk. Extend security requirements to vendors and contractors. Your organization can be compromised through someone else's developer. Bybit lost roughly $1.5 billion after a developer at its wallet vendor was compromised. Ask vendors: Do developers use managed devices? How are they trained on fake-recruiter and malicious-package attacks? How do they prevent password reuse? How do they vet employees and subcontractors? Keep developer training current. Tom's case was identified because someone recognized the fake-interview pattern and reported it instead of running the code. These actors continuously evolve their methods. StoatWaffle is a good example: the risk has moved beyond "don't run code from strangers" to situations where simply opening a trusted folder can trigger execution. Make current threat briefings part of ongoing training for developers, IT staff, and contractors. Hiring has become an attack surface in both directions, and most security programs don't own either end of it. References: Joint NPA/NCO/FBI/DC3/ASD’s ACSC/BND/BfV advisory on North Korean WaterPlum, Sept. 18, 2026: https://www.ic3.gov/CSA/2026/260918.pdf LMG Security, Anatomy of a Job Interview Supply Chain Attack (June 2026) Cyberside Chats, Damaged Goods: When Your New Hire Is Already Compromised (June 9, 2026): https://www.chatcyberside.com/e/damaged-goods-when-your-new-hire-is-already-compromised/ NTT Security, OtterCookie analysis (Jan. 16, 2025): https://jp.security.ntt/insights_resources/tech_blog/en-contagious-interview-ottercookie/ The Hacker News, North Korean hackers abuse VS Code auto-run tasks to deploy StoatWaffle (March 2026): https://thehackernews.com/2026/03/north-korean-hackers-abuse-vs-code-auto.html Microsoft Security Blog, Contagious Interview malware delivered through fake developer job interviews (March 11, 2026): https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/ KnowBe4, How a North Korean Fake IT Worker Tried to Infiltrate Us (July 23, 2024; updated Oct. 19, 2024): https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us LMG Security, North Korea’s Deepfake Remote Workers (Aug. 13, 2025): https://www.lmgsecurity.com/north-koreas-deepfake-remote-workers-how-theyre-getting-inside-u-s-companies-and-how-to-stop-them/ Cyberside Chats, Unmasking the North Korean Cyber Threat (Aug. 12, 2025): https://www.chatcyberside.com/e/unmasking-the-north-korean-cyber-threat/ The Hacker News, Safe{Wallet} confirms North Korean attack on Bybit (March 2025): https://thehackernews.com/2025/03/safewallet-confirms-north-korean.html Infosecurity Magazine, coverage of the WaterPlum advisory.