Skip to main content

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

0
High
News
Published: 09/22/2026 (09/22/2026, 08:37:06 UTC)
Source: SecurityWeek

Description

A joint advisory from the US, Japan, Germany, and Australia details the North Korean WaterPlum campaign, which uses a hiring scheme to target software developers and IT professionals globally. WaterPlum impersonates legitimate companies and recruiting services to infect devices and steal cryptocurrency funds. Japan dismantled its first North Korean laptop farm used to remotely operate infected devices. The campaign has compromised over 30,000 devices in more than 100 countries, stealing funds from over 7,000 cryptocurrency wallets. The group is linked to North Korea's 313 General Bureau and uses sophisticated evasion techniques including AI face-swapping during interviews. The campaign poses risks beyond theft, including potential network infiltration and extortion.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 08:47:54 UTC

Technical Analysis

The WaterPlum campaign is a North Korean cyber operation that targets IT professionals worldwide by posing as legitimate employers, often in AI, cryptocurrency, or NFT sectors. It uses social engineering and malware to infect devices, resulting in theft of cryptocurrency funds totaling approximately $10.71 million. The campaign operates laptop farms—remote device clusters managed by North Korean IT workers via accomplices—to mask their activities. Japan has dismantled its first known laptop farm linked to this group. The advisory highlights the group's ties to North Korea's 313 General Bureau and describes their use of AI face-swapping and other deception techniques during recruitment interviews. The campaign also threatens victim organizations through potential network access and extortion.

Potential Impact

WaterPlum has infected at least 30,000 devices across over 100 countries, stealing funds from more than 7,000 cryptocurrency wallets, with an estimated $10.71 million transferred to North Korea. Beyond financial theft, compromised developers may provide attackers access to their employers' networks, risking exposure of trade secrets and personal data. The campaign's use of laptop farms enables remote operation and obfuscation of attacker locations. The takedown of a laptop farm in Japan marks a significant disruption of the group's infrastructure. The campaign's sophisticated evasion techniques complicate detection and attribution.

Defensive Guidance

No official patch or fix applies as this is a threat actor campaign rather than a software vulnerability. Organizations should be aware of WaterPlum's tactics, including impersonation of legitimate companies and use of AI-based deception during recruitment. Vigilance in verifying candidate identities and behaviors during hiring processes is recommended. Cryptocurrency exchanges and wallet holders should monitor for suspicious activity and employ strong security controls. Law enforcement actions, such as Japan's dismantling of laptop farms, contribute to disruption. Follow updates from official advisories for ongoing mitigation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/japan-dismantles-first-north-korean-laptop-farm-as-us-and-allies-detail-wider-scheme/","fetched":true,"fetchedAt":"2026-09-22T08:47:47.286Z","wordCount":1364}

Threat ID: 6ab240b3f7a7c54106ed87e3

Added to database: 09/22/2026, 08:47:47 UTC

Last enriched: 09/22/2026, 08:47:54 UTC

Last updated: 09/23/2026, 02:01:08 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses