A North Korean-linked hacking group has launched a fresh wave of cyberattacks by impersonating recruiters and technical hiring processes. The campaign, attributed to a cluster named PurpleBravo, has targeted artificial intelligence, cryptocurrency, and financial services firms worldwide. According to Recorded Future's Insikt Group, the operation compromised more than 3,100 IP addresses, with over 20 confirmed victim organizations spanning South Asia, North America, Europe, the Middle East, and Central America. The group is believed to have ties to North Korea's cyber units and has been involved in several crypto thefts totaling billions of dollars over the past year.
Fake Interviews as Attack Vectors: The "Contagious Interview" Technique
Researchers describe the method as "Contagious Interview". Hackers pose as recruiters from tech or crypto companies, reaching out to engineers and developers for technical interviews. During the process, targets are asked to review code, clone GitHub repositories, or complete specific coding tasks. These seemingly benign tests contain hidden malicious code. Once executed on a corporate machine, the hackers gain system access that can spread across the entire internal network.
Geographic Spread and Focus on High-Value Sectors
Insikt Group's monitoring identified at least 3,136 targeted IPs. The attacks specifically prey on industries with high data volumes and frequent money flows: AI research labs, crypto trading firms, and financial institutions. The motives range from intelligence theft to direct fund siphoning and long-term network infiltration.
Evolving Tactics: Fake Identities and Weaponized Tools
The campaign uses multiple fake personas—often claiming to be from Ukraine—and leverages platforms like GitHub, LinkedIn, and Upwork to build credibility. Behind the scenes, PurpleBravo employs cross-platform malware to steal browser credentials, cookies, and enable remote control. Researchers also warn of backdoored developer tools, such as tampered Visual Studio Code projects that execute malicious commands upon opening after the user grants trust.
Cybersecurity professionals emphasize that the weaponization of hiring processes is an escalating threat. Engineers and companies should verify the legitimacy of unexpected recruitment invitations and code tests, and avoid running unverified code on company devices to prevent organization-level breaches.

