North Korean Hackers PurpleBravo Target Crypto and AI Firms via Fake Job Interviews, Over 3,100 IPs Affected

North Korean Hackers PurpleBravo Target Crypto and AI Firms via Fake Job Interviews, Over 3,100 IPs Affected

N
News Editor 01
2026-07-23 06:15:16
Recorded Future's Insikt Group reports that North Korean hacking group PurpleBravo has infiltrated AI and crypto firms through fake job interviews. Over 3,100 IP addresses were targeted, with 20+ confirmed victims globally. Experts urge caution.
North Korea hackersPurpleBravofake job interviewcrypto securitycyber threat

A North Korean-linked hacking group has launched a fresh wave of cyberattacks by impersonating recruiters and technical hiring processes. The campaign, attributed to a cluster named PurpleBravo, has targeted artificial intelligence, cryptocurrency, and financial services firms worldwide. According to Recorded Future's Insikt Group, the operation compromised more than 3,100 IP addresses, with over 20 confirmed victim organizations spanning South Asia, North America, Europe, the Middle East, and Central America. The group is believed to have ties to North Korea's cyber units and has been involved in several crypto thefts totaling billions of dollars over the past year.

Fake Interviews as Attack Vectors: The "Contagious Interview" Technique

Researchers describe the method as "Contagious Interview". Hackers pose as recruiters from tech or crypto companies, reaching out to engineers and developers for technical interviews. During the process, targets are asked to review code, clone GitHub repositories, or complete specific coding tasks. These seemingly benign tests contain hidden malicious code. Once executed on a corporate machine, the hackers gain system access that can spread across the entire internal network.

Geographic Spread and Focus on High-Value Sectors

Insikt Group's monitoring identified at least 3,136 targeted IPs. The attacks specifically prey on industries with high data volumes and frequent money flows: AI research labs, crypto trading firms, and financial institutions. The motives range from intelligence theft to direct fund siphoning and long-term network infiltration.

Evolving Tactics: Fake Identities and Weaponized Tools

The campaign uses multiple fake personas—often claiming to be from Ukraine—and leverages platforms like GitHub, LinkedIn, and Upwork to build credibility. Behind the scenes, PurpleBravo employs cross-platform malware to steal browser credentials, cookies, and enable remote control. Researchers also warn of backdoored developer tools, such as tampered Visual Studio Code projects that execute malicious commands upon opening after the user grants trust.

Cybersecurity professionals emphasize that the weaponization of hiring processes is an escalating threat. Engineers and companies should verify the legitimacy of unexpected recruitment invitations and code tests, and avoid running unverified code on company devices to prevent organization-level breaches.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.