Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
Japan dismantles North Korean laptop farm; US, allies detail WaterPlum campaign.
Summary
Japan, the US, Australia, and Germany have exposed North Korea's 'WaterPlum' campaign, which targets IT professionals by impersonating companies. The group infected over 30,000 devices globally, stealing millions in cryptocurrency and potentially gaining access to employer networks. Japan's authorities dismantled a North Korean laptop farm, a key component of the operation.
Full text
Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as Contagious Interview. The document lays out the threat group’s methods, ties some of its members to North Korea’s broader IT-worker scheme, and describes Japan’s first-ever takedown of a North Korean laptop farm. WaterPlum campaign overview WaterPlum poses as employers to reach software developers and IT professionals, often impersonating real AI, cryptocurrency or NFT companies. The group has also used legitimate recruiting services to make contact, according to the advisory. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries. The advisory says its primary targets were web designers, engineers and specialists in cryptocurrency, blockchain and web3. Funds or account credentials were taken from more than 7,000 cryptocurrency wallets, and the agencies estimate that roughly $10.71 million ultimately reached North Korea. The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee. Advertisement. Scroll to continue reading. The advisory also states that WaterPlum actors and North Korean IT workers have been seen using the same IP addresses, including when accessing laptop farms and applying for jobs. The government agencies noted that the damage does not stop at stolen wallets. A compromised developer can give WaterPlum a path into their employer’s network, and the group has also used stolen data for extortion or to access personal information and trade secrets. Japan targets North Korean laptop farm Part of the scheme relies on so-called laptop farms: locations, often an accomplice’s residence, where devices are set up and then run remotely by North Korean IT workers. These accomplices also manage servers on the workers’ behalf, masking their real location while they carry out paid IT work. According to the advisory, Japan dismantled one such laptop farm this year, the first case of its kind the country has confirmed. “Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan,” the document states. Separately, the FBI says it continues to identify and prosecute US-based individuals who provide facilitation services to North Korean IT workers. Telltale signs that exposed operatives The advisory describes a case from a Japanese cryptocurrency exchange that turned down a suspicious applicant in May 2025. The candidate applied through a VPN with a resume claiming more than ten areas of expertise each across programming languages, blockchain technologies and cloud services. He also claimed to have a European university degree and a vast job experience across Europe and Asia. On a video interview, the applicant said he was born in Malaysia, lived in Finland, and spoke Malay and Chinese as native languages. His English, the advisory notes, “did not match his claimed academic and professional background,” and he could not explain most of the skills listed on his resume. Interviewers who encountered other suspected North Korean IT workers reported similar patterns, including reluctance to meet in person, requests to be paid in cryptocurrency, and applicants who appeared to glance at a second screen as if reading answers. Some calls featured unexplained background voices or repeated audio and video freezes. The agencies noted that WaterPlum operators frequently used AI face-swapping during initial video calls, cutting their feeds minutes into the interview under the guise of technical difficulties to evade detection. Others were observed practicing Japanese pronunciation with text-to-speech tools, relying on free machine-translation services, or stepping away from their usual work on North Korean holidays to watch soccer or play games. Related: FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers Related: North Korean Hackers Deploy New Linux Espionage Toolkit Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Colorado Water Utilities Hit by Cyberattacks Targeting OT SystemsGoogle Confirms Gemini AI Breached Three FirmsAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During Training Latest News US Proposes AI Incident Alert System in Talks With China, Bessent SaysGoogle Hit With $463 Million Fine for EU Location Data Rule BreachFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastDragos Completes NetRise and runZero Acquisitions Following Accenture DealRatHat Android Trojan Uses AI for AutomationRust Team Members and Popular Crate Owners Targeted via Video CallsCrowdSec Confirms Source Code Stolen in Supply Chain Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they a