Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
A joint advisory from the US, Japan, Germany, and Australia details the North Korean WaterPlum campaign, which uses a hiring scheme to target software developers and IT professionals globally. WaterPlum impersonates legitimate companies and recruiting services to infect devices and steal cryptocurrency funds. Japan dismantled its first North Korean laptop farm used to remotely operate infected devices. The campaign has compromised over 30,000 devices in more than 100 countries, stealing funds from over 7,000 cryptocurrency wallets. The group is linked to North Korea's 313 General Bureau and uses sophisticated evasion techniques including AI face-swapping during interviews. The campaign poses risks beyond theft, including potential network infiltration and extortion.
AI Analysis
Technical Summary
The WaterPlum campaign is a North Korean cyber operation that targets IT professionals worldwide by posing as legitimate employers, often in AI, cryptocurrency, or NFT sectors. It uses social engineering and malware to infect devices, resulting in theft of cryptocurrency funds totaling approximately $10.71 million. The campaign operates laptop farms—remote device clusters managed by North Korean IT workers via accomplices—to mask their activities. Japan has dismantled its first known laptop farm linked to this group. The advisory highlights the group's ties to North Korea's 313 General Bureau and describes their use of AI face-swapping and other deception techniques during recruitment interviews. The campaign also threatens victim organizations through potential network access and extortion.
Potential Impact
WaterPlum has infected at least 30,000 devices across over 100 countries, stealing funds from more than 7,000 cryptocurrency wallets, with an estimated $10.71 million transferred to North Korea. Beyond financial theft, compromised developers may provide attackers access to their employers' networks, risking exposure of trade secrets and personal data. The campaign's use of laptop farms enables remote operation and obfuscation of attacker locations. The takedown of a laptop farm in Japan marks a significant disruption of the group's infrastructure. The campaign's sophisticated evasion techniques complicate detection and attribution.
Mitigation Recommendations
No official patch or fix applies as this is a threat actor campaign rather than a software vulnerability. Organizations should be aware of WaterPlum's tactics, including impersonation of legitimate companies and use of AI-based deception during recruitment. Vigilance in verifying candidate identities and behaviors during hiring processes is recommended. Cryptocurrency exchanges and wallet holders should monitor for suspicious activity and employ strong security controls. Law enforcement actions, such as Japan's dismantling of laptop farms, contribute to disruption. Follow updates from official advisories for ongoing mitigation guidance.
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
Description
A joint advisory from the US, Japan, Germany, and Australia details the North Korean WaterPlum campaign, which uses a hiring scheme to target software developers and IT professionals globally. WaterPlum impersonates legitimate companies and recruiting services to infect devices and steal cryptocurrency funds. Japan dismantled its first North Korean laptop farm used to remotely operate infected devices. The campaign has compromised over 30,000 devices in more than 100 countries, stealing funds from over 7,000 cryptocurrency wallets. The group is linked to North Korea's 313 General Bureau and uses sophisticated evasion techniques including AI face-swapping during interviews. The campaign poses risks beyond theft, including potential network infiltration and extortion.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WaterPlum campaign is a North Korean cyber operation that targets IT professionals worldwide by posing as legitimate employers, often in AI, cryptocurrency, or NFT sectors. It uses social engineering and malware to infect devices, resulting in theft of cryptocurrency funds totaling approximately $10.71 million. The campaign operates laptop farms—remote device clusters managed by North Korean IT workers via accomplices—to mask their activities. Japan has dismantled its first known laptop farm linked to this group. The advisory highlights the group's ties to North Korea's 313 General Bureau and describes their use of AI face-swapping and other deception techniques during recruitment interviews. The campaign also threatens victim organizations through potential network access and extortion.
Potential Impact
WaterPlum has infected at least 30,000 devices across over 100 countries, stealing funds from more than 7,000 cryptocurrency wallets, with an estimated $10.71 million transferred to North Korea. Beyond financial theft, compromised developers may provide attackers access to their employers' networks, risking exposure of trade secrets and personal data. The campaign's use of laptop farms enables remote operation and obfuscation of attacker locations. The takedown of a laptop farm in Japan marks a significant disruption of the group's infrastructure. The campaign's sophisticated evasion techniques complicate detection and attribution.
Defensive Guidance
No official patch or fix applies as this is a threat actor campaign rather than a software vulnerability. Organizations should be aware of WaterPlum's tactics, including impersonation of legitimate companies and use of AI-based deception during recruitment. Vigilance in verifying candidate identities and behaviors during hiring processes is recommended. Cryptocurrency exchanges and wallet holders should monitor for suspicious activity and employ strong security controls. Law enforcement actions, such as Japan's dismantling of laptop farms, contribute to disruption. Follow updates from official advisories for ongoing mitigation guidance.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/japan-dismantles-first-north-korean-laptop-farm-as-us-and-allies-detail-wider-scheme/","fetched":true,"fetchedAt":"2026-09-22T08:47:47.286Z","wordCount":1364}
Threat ID: 6ab240b3f7a7c54106ed87e3
Added to database: 09/22/2026, 08:47:47 UTC
Last enriched: 09/22/2026, 08:47:54 UTC
Last updated: 09/23/2026, 02:01:08 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.