Japan Dismantles North Korean Laptop Farm as US and Allies Expose Wider Cyber Scheme

www.news4hackers.com-japan-dismantles-north-korean-laptop-farm-as-us-and-allies-expose-wider-cyber-scheme-japan-dismantles-north-korean-laptop-farm-as-us-and-allies-expose-wider-cyber-scheme

Law enforcement and intelligence agencies from Japan, the United States, Australia, and Germany have issued a joint advisory linking a prolonged recruitment scheme to a North Korean threat group designated as WaterPlum, also referred to as Contagious Interview. The document outlines the group’s tactics, connects some members to North Korea’s broader IT-worker program, and details Japan’s first confirmed takedown of a North Korean laptop farm.

WaterPlum campaign overview

WaterPlum operates by masquerading as legitimate employers to target software developers and IT professionals, frequently impersonating companies in artificial intelligence, cryptocurrency, and NFT sectors. The group has also leveraged authentic recruitment platforms to establish contact, according to the advisory. Between December 2025 and July 2026, WaterPlum compromised at least 30,000 devices across over 100 countries. The primary targets included web designers, engineers, and specialists in cryptocurrency, blockchain, and web3 technologies. The advisory reports that the group stole funds or account credentials from more than 7,000 cryptocurrency wallets, with an estimated $10.71 million funneled to North Korea. The National Police Agency of Japan and the FBI have determined that WaterPlum operators and certain North Korean IT workers are affiliated with the 313 General Bureau of the Munitions Industry Department under the Workers’ Party of Korea’s Central Committee. The document also notes that WaterPlum actors and North Korean IT workers have shared IP addresses, particularly when accessing laptop farms or applying for roles. Beyond financial theft, the advisory highlights that compromised developers provide WaterPlum with access to employer networks. The group has also exploited stolen data for extortion or to obtain personal information and trade secrets.

Japan targets North Korean laptop farm

A critical component of the scheme involves laptop farms—locations, often controlled by accomplices, where devices are configured and remotely operated by North Korean IT workers. These accomplices manage servers on behalf of the workers, obscuring their true locations while they perform paid IT tasks. Japan’s authorities dismantled one such laptop farm this year, marking the country’s first confirmed case of this nature. The advisory states that Japanese authorities gathered evidence showing the cyber actor group transferred hundreds of millions of Japanese yen in cryptocurrency to foreign destinations. Meanwhile, the FBI continues to identify and prosecute U.S.-based individuals who facilitate services for North Korean IT workers.

Telltale signs that exposed operatives

The advisory details a case involving a Japanese cryptocurrency exchange that rejected a suspicious applicant in May 2025. The candidate used a VPN and submitted a resume claiming expertise in over ten programming languages, blockchain technologies, and cloud services. The resume also cited a European university degree and extensive work experience across Europe and Asia. During a video interview, the applicant claimed to be from Malaysia, residing in Finland, and fluent in Malay and Chinese. However, his English proficiency did not align with his stated background, and he struggled to explain most of the skills listed on his resume. Interviewers who encountered other suspected North Korean IT workers reported similar patterns, including reluctance to meet in person, requests for cryptocurrency payments, and signs of reading from a secondary screen during calls. Some interactions featured unexplained background noises or repeated audio/video disruptions. The advisory notes that WaterPlum operators frequently employed AI-generated face swaps during initial video calls, terminating their feeds mid-interview under the pretense of technical issues to avoid detection. Others were observed practicing Japanese pronunciation using text-to-speech tools, relying on free machine-translation services, or deviating from work schedules on North Korean holidays to engage in recreational activities.



About Author

en_USEnglish