TechDogs-"Japan Dismantles First North Korean Laptop Farm As WaterPlum Hits 30,000 Devices"

Cyber Security

Japan Dismantles First North Korean Laptop Farm As WaterPlum Hits 30,000 Devices

By TechDogs Bureau

TD NewsDesk

Updated on Tue, Sep 22, 2026

Overall Rating

Japan has dismantled its first identified “laptop farm” used by North Korean IT workers, as an international investigation links the WaterPlum cyber campaign to at least 30,000 compromised devices across more than 100 countries and over 7,000 cryptocurrency wallets, according to Australian Cyber Security Centre.

 

The operation forms part of a wider scheme in which threat actors allegedly pose as employers or remote IT workers to steal cryptocurrency, gain access to corporate systems, and generate revenue for North Korea.

 

TL;DR

  • Japanese authorities dismantled the country’s first identified laptop farm used to support North Korean remote IT workers.
  • WaterPlum allegedly compromised at least 30,000 devices across more than 100 countries and targeted over 7,000 cryptocurrency wallets.
  • Authorities say the campaign uses fake recruitment, malicious coding assignments, remote-access malware, stolen identities, and AI-assisted techniques to target IT professionals.
 

Law enforcement and intelligence agencies from Japan, the United States, Australia, and Germany have jointly detailed the activities of WaterPlum, a North Korean cyber actor group commonly referred to as Contagious Interview.

According to the joint cybersecurity advisory published through the FBI’s Internet Crime Complaint Center, the National Police Agency of Japan and the FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of North Korea’s Munitions Industry Department.

The group allegedly poses as prospective employers and targets software developers and other IT professionals with attractive job opportunities. Attackers have impersonated legitimate artificial intelligence, cryptocurrency, and NFT companies and have also approached victims through recruitment services.

During online interviews or technical assessments, victims can be instructed to download files or execute code presented as part of a coding assignment or as a fix for a supposed video-conferencing problem.

The Australian Cyber Security Centre said malicious NPM packages used in the attacks have contained malware including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Once installed, the malware can provide backdoor access, steal sensitive information, and maintain remote access to compromised systems.

 

WaterPlum Allegedly Compromised 30,000 Devices

 

Authorities say WaterPlum exploited at least 30,000 computers across more than 100 countries between around December 2025 and July 2026.

Its targets included web designers, engineers, and professionals working with cryptocurrency, blockchain, and Web3 technologies. The campaign allegedly obtained funds or credentials from more than 7,000 cryptocurrency wallets and transferred cryptocurrency worth 1.7 billion Japanese yen, approximately $10.71 million, to North Korea.

The attacks can also create risks beyond an individual developer’s computer.

The joint advisory warns that compromising a developer may give attackers an opportunity to reach the victim’s employer, potentially enabling espionage, intellectual property theft, or further movement through corporate systems. Stolen information can include browser credentials, keystrokes, screenshots, cryptocurrency wallet data, passports, driver’s licences, and other files.

As SecurityWeek reported, authorities have also observed WaterPlum actors using AI face-swapping during initial video interviews before switching off their cameras, often citing supposed technical problems.

 

Japan Dismantles Its First North Korean Laptop Farm

 

A key part of the scheme involves so-called laptop farms.

These are physical locations, often an enabler’s residence, where computers supplied for employment are kept while workers located elsewhere remotely control them. This can make an overseas worker appear to employers and online services as if they are working from the country where the laptop is physically located.

Japan’s National Police Agency confirmed that Japanese authorities successfully identified, investigated, and dismantled such an operation for the first time in the country.

The joint advisory states that Japanese investigators found evidence showing the cyber actors transferred “several hundred million Japanese yen” in cryptocurrency to locations outside Japan.

The tactic is not unique to Japan. US authorities have been pursuing people accused of hosting computers on behalf of North Korean remote workers.

In April, the US Department of Justice announced prison sentences for two US nationals who operated laptop farms supporting a scheme that generated more than $5 million in revenue for North Korea and involved remote workers gaining jobs at more than 100 US companies.

Another US Department of Justice case announced in May 2026 involved two US nationals sentenced for facilitating separate remote IT worker schemes by hosting company-issued computers at their residences.

 

Fake Job Interviews Remain A Key Entry Point

 

The latest advisory also detailed a May 2025 case involving a Japanese cryptocurrency exchange.

A suspicious engineering applicant claimed extensive expertise across programming languages, blockchain technologies, and cloud services, as well as a European education and employment history across Europe and Asia. During the interview, however, authorities said the applicant struggled to explain many of the skills listed on the resume.

The company rejected the applicant and suffered no reported damage. Other warning signs identified by authorities include refusing in-person meetings, asking to receive salary in cryptocurrency, repeatedly looking at another monitor during interviews, unexplained background voices, and repeated audio or video interruptions.

Authorities recommend that developers avoid executing untrusted code, particularly on systems containing cryptocurrency or sensitive personal data, and use sandboxed or virtual environments when unknown code must be examined.

Businesses are also advised to restrict access rights, verify applicant identities and locations where possible, and use endpoint detection and response tools to identify suspicious activity.

The wider campaign shows how a seemingly routine remote hiring process can serve two purposes at once: providing an entry point for malware attacks while also helping overseas IT workers conceal their actual locations and obtain paid work under false identities.

First published on Tue, Sep 22, 2026

Enjoyed what you've read so far? Great news - there's more to explore!

Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.

Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.

Dive into TechDogs' treasure trove today and Know Your World of technology!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light