Key Highlights
- Japan, the United States, Australia, and Germany jointly attributed a global crypto-theft campaign to WaterPlum, a North Korea-backed group also known as Contagious Interview, on September 18.
- The campaign infected at least 30,000 machines across more than 100 countries, stole roughly 7,000 crypto wallet records, and moved an estimated 1.7 billion yen (about $11.5 million) in digital assets.
- Japanese police disclosed the first confirmed domestic “laptop farms” operated remotely by North Korean IT workers, which funneled hundreds of millions of yen overseas, while a Japanese exchange detected North Korean applicants posing as engineers during interviews.
Four Nations Issue Coordinated Attribution Against WaterPlum
On September 18, Japan’s National Police Agency (NPA) joined counterparts in the United States, Australia, and Germany to release a joint advisory publicly naming WaterPlum — also tracked as Contagious Interview — as the threat actor behind a sprawling cryptocurrency theft operation. The statement places the group under the direct command of the 313th General Bureau of the Korean Workers’ Party Central Committee’s Military Industry Department, marking a rare, synchronized diplomatic and law-enforcement effort to expose North Korean cyber infrastructure. According to the NPA, the findings draw on intelligence supplied by private-sector partners and investigations conducted by its Kanto Regional Police Bureau cyber division alongside prefectural police units.
Scale and Mechanics of the WaterPlum Campaign
The advisory details a campaign that has compromised at least 30,000 machines across more than 100 countries and regions, including Japan. Attackers leveraged fake job offers targeting IT engineers — a hallmark of the Contagious Interview scheme — to deliver malware designed to harvest crypto wallet credentials. Approximately 7,000 wallet records were stolen, and the group moved at least 1.7 billion yen (roughly $11.5 million) in digital assets. The disclosure aligns with a broader pattern of North Korean cyber operations that have already breached 1,640 companies across 57 countries, underscoring the persistent and industrialized nature of the regime’s revenue-generation apparatus.
Laptop Farms and Infiltration of Japanese Tech Hiring
Beyond the malware campaign, the advisory reveals a parallel threat vector: Japanese investigators identified domestic “laptop farms” — physical locations where hardware is hosted and remotely operated by North Korean IT workers dispatched abroad to earn foreign currency for the regime. These operations channeled hundreds of millions of yen overseas, including in cryptocurrency. In a related development, a Japanese cryptocurrency exchange reported receiving job applications from North Korean IT workers for engineering roles and detected the deception during the interview process. The findings follow other recent North Korean crypto activity, including Lazarus Group-linked Bitcoin sales tracked on the Hyperliquid platform.
Why This Matters
The joint announcement signals a strategic shift: four governments have elevated crypto theft from a financial-crime concern to a national-security and economic-threat priority. By explicitly naming the command structure — the 313th General Bureau — the attribution aims to disrupt the operational chain and deter private-sector enablers. For exchanges, wallet providers, and development teams, the practical imperative is clear: unsolicited job offers and recruitment messages must be treated as potential intrusion vectors, and remote-hiring vetting processes need rigorous identity verification and technical screening. The NPA has urged IT engineers and private companies to review the advisory in full and harden their defenses against a threat that blends social engineering, supply-chain compromise, and state-directed financial crime.
Frequently Asked Questions
What is WaterPlum and how does it relate to Contagious Interview?
WaterPlum is the name used in the joint advisory for a North Korea-backed cyber group also known as Contagious Interview. The group operates under the 313th General Bureau of the Korean Workers’ Party Central Committee’s Military Industry Department and specializes in targeting IT engineers through fake job offers to deploy wallet-stealing malware.
How can organizations defend against WaterPlum-style attacks?
The advisory recommends treating unsolicited recruitment messages as a security risk, implementing strict identity verification for remote hires, monitoring for anomalous endpoint behavior, and reviewing the joint technical guidance published by the four nations’ authorities. Companies should also share threat intelligence with industry peers and law enforcement.
What is the significance of the “laptop farm” discovery in Japan?
It marks the first time Japanese police have confirmed domestic infrastructure — physical locations hosting laptops remotely controlled by North Korean IT workers — being used to funnel hundreds of millions of yen overseas. This reveals a hybrid model where cyber-enabled theft and labor-export sanctions evasion converge, expanding the threat surface beyond pure malware campaigns.

Leave a Reply