Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme

Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme

Posted on September 22, 2026 By CWS

Authorities from Japan, the United States, Australia, and Germany have issued a joint advisory unveiling a sophisticated recruitment scam orchestrated by a North Korean group known as WaterPlum, also referred to as Contagious Interview. This advisory highlights the group’s tactics and marks Japan’s inaugural dismantling of a North Korean-operated laptop farm.

WaterPlum’s Deceptive Operations

WaterPlum deceives IT professionals by masquerading as legitimate employers in sectors such as AI, cryptocurrency, and NFTs. The group exploits real recruitment platforms to reach out to software developers and technology experts, as detailed in the advisory.

From December 2025 to July 2026, WaterPlum managed to infiltrate over 30,000 devices in more than 100 nations. Their primary victims included web designers and cryptocurrency specialists, leading to unauthorized access to over 7,000 digital wallets. An estimated $10.71 million was funneled to North Korea through these operations.

The National Police Agency of Japan and the FBI have linked WaterPlum operators with North Korean IT workers under the 313 General Bureau, part of the regime’s central committee. Evidence shows shared IP usage between these actors, furthering their infiltration strategies.

Japan’s Crackdown on Laptop Farms

Laptop farms play a crucial role in WaterPlum’s operations by housing devices managed remotely by North Korean IT workers. These setups, often based in accomplices’ homes, facilitate covert IT work by masking actual locations.

Japan has successfully dismantled one such setup this year, marking a significant milestone in countering these cyber threats. This dismantling revealed substantial cryptocurrency transfers amounting to hundreds of millions of yen to foreign entities.

Meanwhile, the FBI remains vigilant in identifying and prosecuting individuals in the US who assist North Korean IT workers in these illicit activities.

Red Flags and Detection Techniques

A notable case involved a Japanese cryptocurrency exchange rejecting an applicant in May 2025, whose resume was flagged for dubious claims. Despite asserting expertise in numerous programming and blockchain technologies, discrepancies arose during a video interview.

The applicant’s language proficiency did not align with his purported academic background, raising suspicions. Similar patterns have emerged with other suspected North Korean operatives, including requests for cryptocurrency payments and reliance on AI face-swapping during video calls.

Further observations included the use of text-to-speech for language practice and inconsistent behavior during North Korean holidays, highlighting the intricate methods employed by WaterPlum to evade detection.

The advisory serves as a reminder of the persistent cyber threats posed by North Korean operations. As global collaboration intensifies, the dismantling of such schemes becomes crucial in safeguarding digital ecosystems.

Security Week News Tags:AI impersonation, blockchain security, crypto theft, Cryptocurrency, Cybercrime, Cybersecurity, digital extortion, FBI, global cyber threats, international cooperation, IT workers, Japan, laptop farms, North Korea, WaterPlum

Post navigation

Previous Post: SideCopy Shifts Focus to Indian Academia with ReverseRAT

Related Posts

Anubis Ransomware Packs a Wiper to Permanently Delete Files Anubis Ransomware Packs a Wiper to Permanently Delete Files Security Week News
Unauthenticated RCE Flaw Patched in DrayTek Routers Unauthenticated RCE Flaw Patched in DrayTek Routers Security Week News
U.S. Accuses Hacker in Uranium Exchange Breach U.S. Accuses Hacker in Uranium Exchange Breach Security Week News
High-Severity Vulnerabilities Patched in Tenable Nessus Agent High-Severity Vulnerabilities Patched in Tenable Nessus Agent Security Week News
Berlin Refuses Ransom After Major Data Breach Berlin Refuses Ransom After Major Data Breach Security Week News
Supply Chain Attack Hits SAP NPM Packages Supply Chain Attack Hits SAP NPM Packages Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark