Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

MediumSecurityWeek · Eduard Kovacs·

At a glance

Severity
Medium
Used in attacks
No flaws named
Reported by
1 outlet

Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as Contagious Interview

The document lays out the threat group’s methods, ties some of its members to North Korea’s broader IT-worker scheme, and describes Japan’s first-ever takedown of a North Korean laptop farm.

WaterPlum campaign overview

WaterPlum poses as employers to reach software developers and IT professionals, often impersonating real AI, cryptocurrency or NFT companies. The group has also used legitimate recruiting services to make contact, according to the advisory.

Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries. The advisory says its primary targets were web designers, engineers and specialists in cryptocurrency, blockchain and web3.

Funds or account credentials were taken from more than 7,000 cryptocurrency wallets, and the agencies estimate that roughly $10.71 million ultimately reached North Korea.

The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee. 

Advertisement. Scroll to continue reading.

The advisory also states that WaterPlum actors and North Korean IT workers have been seen using the same IP addresses, including when accessing laptop farms and applying for jobs.

The government agencies noted that the damage does not stop at stolen wallets. A compromised developer can give WaterPlum a path into their employer’s network, and the group has also used stolen data for extortion or to access personal information and trade secrets.

Japan targets North Korean laptop farm

Part of the scheme relies on so-called laptop farms: locations, often an accomplice’s residence, where devices are set up and then run remotely by North Korean IT workers. These accomplices also manage servers on the workers’ behalf, masking their real location while they carry out paid IT work.

According to the advisory, Japan dismantled one such laptop farm this year, the first case of its kind the country has confirmed. 

“Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan,” the document states.

Separately, the FBI says it continues to identify and prosecute US-based individuals who provide facilitation services to North Korean IT workers.

Telltale signs that exposed operatives

The advisory describes a case from a Japanese cryptocurrency exchange that turned down a suspicious applicant in May 2025. 

The candidate applied through a VPN with a resume claiming more than ten areas of expertise each across programming languages, blockchain technologies and cloud services. He also claimed to have a European university degree and a vast job experience across Europe and Asia.

On a video interview, the applicant said he was born in Malaysia, lived in Finland, and spoke Malay and Chinese as native languages. His English, the advisory notes, “did not match his claimed academic and professional background,” and he could not explain most of the skills listed on his resume. 

Interviewers who encountered other suspected North Korean IT workers reported similar patterns, including reluctance to meet in person, requests to be paid in cryptocurrency, and applicants who appeared to glance at a second screen as if reading answers. Some calls featured unexplained background voices or repeated audio and video freezes.

The agencies noted that WaterPlum operators frequently used AI face-swapping during initial video calls, cutting their feeds minutes into the interview under the guise of technical difficulties to evade detection.

Others were observed practicing Japanese pronunciation with text-to-speech tools, relying on free machine-translation services, or stepping away from their usual work on North Korean holidays to watch soccer or play games.

Related: FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers

Related: North Korean Hackers Deploy New Linux Espionage Toolkit

Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.

Coverage

One outlet has carried this so far.

  1. SecurityWeekEstablished SourceFirst reported

    2026-09-22 08:37 UTC

Related stories