Japan Shut a North Korean Laptop Farm as Allies Say WaterPlum Hit 30,000 Devices for Pyongyang
Japan dismantled its first North Korean laptop farm as the US, Australia, and Germany detailed WaterPlum, a fake-hiring campaign that infected at least 30,000 devices and sent about $10.71 million to Pyongyang.

Japan has dismantled its first confirmed North Korean laptop farm, and in a joint advisory with the United States, Australia, and Germany, the allies laid out the scale of the operation behind it. They attribute a long-running hiring scam they call WaterPlum, also known as Contagious Interview, to North Korea, and say it infected at least 30,000 devices across more than 100 countries.
The money moved fast. Between December 2025 and July 2026 the group drained funds or account credentials from more than 7,000 cryptocurrency wallets, and the agencies estimate that roughly $10.71 million ultimately reached North Korea.
WaterPlum poses as an employer to reach software developers, often impersonating real AI, crypto, or NFT companies, and sometimes working through legitimate recruiting services. Its main targets are web designers, engineers, and specialists in cryptocurrency, blockchain, and web3.
The laptop farm is the physical anchor. It is usually an accomplice's home where devices are set up and then run remotely by North Korean IT workers, masking their real location while they collect paychecks. Japanese authorities found evidence that the operation moved several hundred million yen in cryptocurrency out of the country.
Japan's National Police Agency and the FBI assess that WaterPlum operators and some of North Korea's remote IT workers answer to the same part of the regime, the 313 General Bureau of the Munitions Industry Department under the Workers' Party Central Committee. Investigators have seen the two groups using the same IP addresses, including when logging into laptop farms and applying for jobs.
Coverage of the campaign names a cluster of malware families tied to it, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. A single compromised developer can hand the group a path into an employer's network, and stolen data has been used for extortion or to reach personal information and trade secrets.
The tell is often the interview itself. The agencies say WaterPlum operators frequently used AI face-swapping on video calls, then cut the feed minutes in while blaming technical trouble to avoid detection. Others were caught practicing Japanese pronunciation with text-to-speech tools, leaning on free machine translation, glancing at a second screen as if reading answers, asking to be paid in crypto, or refusing to meet in person.
One case makes the pattern concrete. A Japanese cryptocurrency exchange turned an applicant away in May 2025 after he applied over a VPN with a resume claiming more than ten areas of expertise across programming languages, blockchain, and cloud. On camera he said he was born in Malaysia and lived in Finland, but his English did not match the background he claimed, and he could not explain most of the skills he had listed.
The law enforcement picture sits behind a threat Cyberpresso has already tracked at the technical level, including the campaign's shift to Mac installer malware. It also fits a wider pattern of state-linked and criminal crews professionalizing, like the groups now fighting over stolen leak sites.
The advisory is a joint intelligence and law enforcement warning paired with one takedown, not proof that every one of those 30,000 machines is still infected or a fresh US indictment. What it does establish is a direct funding line: a fake job offer, a compromised laptop, and about $10.71 million routed home to a sanctioned weapons bureau.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free