Authorities from Japan, the United States, Australia, and Germany have issued a joint advisory unveiling a sophisticated recruitment scam orchestrated by a North Korean group known as WaterPlum, also referred to as Contagious Interview. This advisory highlights the group’s tactics and marks Japan’s inaugural dismantling of a North Korean-operated laptop farm.
WaterPlum’s Deceptive Operations
WaterPlum deceives IT professionals by masquerading as legitimate employers in sectors such as AI, cryptocurrency, and NFTs. The group exploits real recruitment platforms to reach out to software developers and technology experts, as detailed in the advisory.
From December 2025 to July 2026, WaterPlum managed to infiltrate over 30,000 devices in more than 100 nations. Their primary victims included web designers and cryptocurrency specialists, leading to unauthorized access to over 7,000 digital wallets. An estimated $10.71 million was funneled to North Korea through these operations.
The National Police Agency of Japan and the FBI have linked WaterPlum operators with North Korean IT workers under the 313 General Bureau, part of the regime’s central committee. Evidence shows shared IP usage between these actors, furthering their infiltration strategies.
Japan’s Crackdown on Laptop Farms
Laptop farms play a crucial role in WaterPlum’s operations by housing devices managed remotely by North Korean IT workers. These setups, often based in accomplices’ homes, facilitate covert IT work by masking actual locations.
Japan has successfully dismantled one such setup this year, marking a significant milestone in countering these cyber threats. This dismantling revealed substantial cryptocurrency transfers amounting to hundreds of millions of yen to foreign entities.
Meanwhile, the FBI remains vigilant in identifying and prosecuting individuals in the US who assist North Korean IT workers in these illicit activities.
Red Flags and Detection Techniques
A notable case involved a Japanese cryptocurrency exchange rejecting an applicant in May 2025, whose resume was flagged for dubious claims. Despite asserting expertise in numerous programming and blockchain technologies, discrepancies arose during a video interview.
The applicant’s language proficiency did not align with his purported academic background, raising suspicions. Similar patterns have emerged with other suspected North Korean operatives, including requests for cryptocurrency payments and reliance on AI face-swapping during video calls.
Further observations included the use of text-to-speech for language practice and inconsistent behavior during North Korean holidays, highlighting the intricate methods employed by WaterPlum to evade detection.
The advisory serves as a reminder of the persistent cyber threats posed by North Korean operations. As global collaboration intensifies, the dismantling of such schemes becomes crucial in safeguarding digital ecosystems.
