Japan's National Police Agency, the US FBI and Department of Defense Cyber Crime Center, Australia's Signals Directorate, and Germany's Federal Intelligence Service and Federal Office for the Protection of the Constitution published a joint advisory on September 18, 2026, formally attributing a sprawling North Korean hiring scheme to a group the six agencies now jointly call WaterPlum. The advisory's headline disclosure: Japanese authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" inside Japan — the first confirmed case of its kind in the country — while the report as a whole puts hard numbers on eight months of a campaign that has infected tens of thousands of devices worldwide.
The Advisory: Four Nations, One Name for WaterPlum
WaterPlum is not a new actor — it is a new, agreed-upon name for a cluster the security industry has tracked since 2023 under a long list of aliases: Contagious Interview, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, UNC5342, Void Dokkaebi, and Recorded Future's PurpleBravo. The September 18 advisory was issued under a formal "public attribution" process, a mechanism agencies use specifically to name a state or group behind malicious cyber activity in the hope that public exposure itself has a deterrent effect.
The Japanese National Police Agency and the FBI assess that WaterPlum's operators — along with a subset of the North Korean nationals working ordinary remote IT jobs — answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, a unit that sits under the Workers' Party of Korea's Central Committee. That line of attribution matters because it ties the fraudulent-hiring and laptop-farm side of North Korea's overseas revenue operation to the same hacking apparatus behind WaterPlum's malware campaigns, rather than treating them as separate problems.
How WaterPlum Operates
WaterPlum's core technique, publicly known since 2023 as "Contagious Interview," targets individual software developers, web designers, and cryptocurrency or Web3 specialists rather than corporate networks directly. Operators pose as recruiters on LinkedIn, GitHub, and freelance and gig-work platforms, often impersonating real AI, NFT, or cryptocurrency companies to build trust with a candidate. Once a target agrees to an "interview," they're asked to run code to complete a coding assignment or to fix a supposed video-conferencing error — code that is actually a malicious npm package or a poisoned Visual Studio Code project. Running it drops one of five active backdoor families the group maintains: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle.
The advisory also confirms tradecraft researchers had already flagged: WaterPlum operators use AI face-swapping software to sit through live video interviews, then abruptly turn off their cameras and blame network problems when asked to prove their identity. Stolen identity documents captured during these attacks are reused later, letting North Korean IT workers impersonate the original victims to apply for other jobs.
Laptop Farms: How North Korea Hides Its Workers
The "laptop farm" is the physical infrastructure that makes North Korea's broader overseas IT-worker fraud scheme possible. A facilitator — often paid for the arrangement — hosts a company-issued laptop at their own residence or a small office. Instead of the hired "employee" using the machine directly, a North Korean IT worker connects to it remotely, doing the actual work from North Korea, China, Russia, or in smaller numbers from Africa or Southeast Asia. The facilitator keeps the laptop running, manages the servers on the worker's behalf, and helps route traffic so the employer's network sees a plausible, domestic-looking connection rather than a login from Pyongyang.
Investigators found the connective tissue between WaterPlum's hacking campaign and this IT-worker infrastructure directly in the data: IP addresses used in WaterPlum attacks matched IP addresses North Korean IT workers used to connect to laptop farms and to crowdsourcing job platforms. In some arrangements, employer payroll payments landed in bank accounts controlled by the facilitator, who then forwarded the money onward, sometimes taking a cut.
Japan's First Takedown, and the Numbers Behind It
Acting on that infrastructure overlap, Japan's National Police Agency says it identified, investigated, and dismantled a laptop farm run by a facilitator inside Japan this year — the first case of its kind the country has confirmed. Authorities found evidence that several hundred million yen tied to the operation had already been transferred overseas before the farm was shut down. In a separate incident cited in the advisory, a suspect connected to the investigation had applied directly for a position at Japanese cryptocurrency exchange bitFlyer and was turned down, illustrating that North Korean operators also attempt to walk straight through the front door at crypto firms' own hiring pipelines.
Zooming out to the campaign as a whole, the joint advisory quantifies eight months of activity: between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries. Credentials or funds were stolen from over 7,000 cryptocurrency wallets, and the agencies estimate roughly $10.71 million (about 1.7 billion Japanese yen) ultimately reached North Korea. For scale, comparable facilitator schemes prosecuted separately in the United States have been smaller — two US men received 18-month prison sentences earlier in 2026 for helping North Korean workers remotely access company laptops across nearly 70 companies, generating over $1.2 million.
Beyond Crypto Theft: The Espionage Risk
The agencies were explicit that the damage doesn't stop at stolen wallets. A compromised developer's machine, or a laptop farm's remote-access foothold inside a legitimate company, can become a launchpad into that company's broader network — enabling espionage, intellectual property theft, and lateral movement well beyond the original victim. The advisory cites cases where North Korean IT workers extorted employers over payment disputes and published proprietary source code publicly in retaliation, and another where a worker hired for routine website maintenance instead defaced the site and knocked it offline entirely.
Why This Matters
This advisory reframes two things that have often been discussed separately — the "Contagious Interview" fake-recruiter malware campaign and North Korea's fraudulent remote-IT-worker scheme — as two arms of the same operation, run out of the same part of the regime. WaterPlum's malware harvests developer and crypto-wallet credentials, and the same IP infrastructure it uses shows up connecting to laptop farms where North Korean nationals are doing paid IT work under a stolen or fabricated identity. For a hiring manager or a security team, the practical lesson is that "job candidate ran suspicious code" and "remote employee behaves oddly and won't turn on their camera" are not two unrelated risk categories anymore — they're two entry points into the same pipeline, and both ultimately fund North Korea's weapons programs.
Japan's first confirmed laptop-farm dismantlement also signals that a piece of this scheme long documented mainly through US Justice Department indictments is now being actively investigated and shut down elsewhere, using the same IP-correlation tradecraft the advisory lays out. More such takedowns, in more countries, should be expected.
Protective Measures
- Treat "run this code to interview" as a red flag. Never execute unreviewed code, npm packages, or IDE projects sent by a recruiter or hiring contact before employment starts, even under time pressure to "complete the assignment."
- Verify remote hires beyond a resume and a video call. Face-swapping software defeats casual visual verification; pair background checks with identity-document validation and, where feasible, a live in-person or notarized identity check for fully remote hires with system access.
- Watch for camera avoidance and network excuses during interviews and onboarding. A pattern of "camera off, blaming connectivity" during video calls is a known WaterPlum tell, not just bad Wi-Fi.
- Monitor for anomalous remote-access patterns on company-issued hardware. Laptop farms rely on persistent remote-access tooling running on a device that's supposed to be sitting with a named employee; endpoint monitoring that flags unexpected remote-desktop or KVM-over-IP software is a practical detection layer.
- Scan freelance and gig-platform hires for the same red flags as full-time roles. WaterPlum and North Korean IT workers both operate through crowdsourcing and freelance portals, not just traditional job boards.
- Assume a compromised developer machine is a network incident, not just a wallet-theft incident. Credential theft from a single infected device can be the first step toward espionage or IP theft against the employer, not the end of the attack.
Sources
- SecurityWeek — Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
- The Hacker News — Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- The Record — North Korean hackers infect thousands of devices across 100 countries as part of 'WaterPlum' campaign
- BleepingComputer — North Korean WaterPlum hackers infected 30,000 devices worldwide