North Korean Hackers Hit 3,100+ IPs via Fake Job Interviews, Targeting Crypto and AI Firms

North Korean Hackers Hit 3,100+ IPs via Fake Job Interviews, Targeting Crypto and AI Firms

N
News Editor 01
2026-07-23 03:55:14
North Korean hackers used fake job interviews to target 3,136 IP addresses and at least 20 organizations in crypto, AI, and other sectors, stealing over $2 billion in crypto in 2025 alone.
North Koreacryptocurrencycybersecurityfake job interviewsAI

Cybersecurity researchers at Recorded Future's Insikt Group have uncovered a wide-ranging campaign by North Korean threat actors who reached 3,136 individual IP addresses and at least 20 organizations through fraudulent job interviews. Tracked as PurpleBravo (also known as Contagious Interview), the operation targets firms in artificial intelligence, cryptocurrency, financial services, IT, marketing, and software development.

How the Fake Interview Trap Works

Attackers pose as recruiters on LinkedIn, using AI-generated profile photos and fake company websites to appear legitimate. They guide candidates through a seemingly normal hiring process, then ask them to complete coding assessments that require downloading malicious files from GitHub repositories. Kenneth Kinion, CEO of Validin, described the strategy's effectiveness: going after job seekers gives North Korean actors a huge advantage—they take over the entire hiring process and make it feel completely legitimate.

The danger escalates when candidates run these assessments on company-issued devices. Recorded Future's analysis notes that in several cases, job seekers executed malicious code on corporate devices, creating organizational exposure beyond the individual. Jamf Threat Labs identified malicious Microsoft Visual Studio Code projects as the primary delivery method for backdoors including BeaverTail, a JavaScript infostealer, and GolangGhost, a Go-based backdoor.

The group maintains multiple fraudulent GitHub repositories and operates fake crypto companies like BlockNovas LLC, Angeloper Agency, and SoftGlide LLC to post jobs on platforms such as CryptoJobsList and Upwork.

Sophisticated Infrastructure Network

PurpleBravo manages two distinct command-and-control server sets hosted across 17 different providers, all administered through Astrill VPN from Chinese IP ranges—a service consistently linked to North Korean operations. Researchers discovered the attackers operate from China, Russia, and Pakistan, using Russian IP addresses to connect to VPS servers. The campaign overlaps with another North Korean initiative called Wagemole, where IT workers seek unauthorized employment under stolen identities. Recorded Future found significant tactical connections between operators of both campaigns.

Over $2 Billion in Crypto Stolen

The financial motive is substantial. Blockchain analytics firm Chainalysis reports North Korean hacking groups stole $2.02 billion in cryptocurrency during 2025 alone, pushing their total haul to $6.75 billion—funds believed to support the regime's nuclear and missile programs. Security experts warn that the 20 confirmed victim organizations likely represent only a fraction of actual impact, given the acute supply chain risks. Many targeted firms serve large customer bases, potentially exposing downstream clients.

Organizations are urged to enhance verification for job applicants, conduct mandatory video interviews with identity checks, deploy tools to detect AI-generated images, and monitor development environments for suspicious activity. The campaign demonstrates how North Korean cyber operations continue evolving, blurring the line between routine business and national security threats.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.