North Korea hackers stole crypto using fake job interviews

State-linked North Korean hackers posed as employers in technical interviews to install malware or capture credentials, diverting millions in cryptocurrency worldwide.

State-linked North Korean hackers used fake IT job interviews to install malware or capture credentials and diverted millions of dollars in cryptocurrency from victims around the world.

Security firms and investigators report recruiters and interviewers posed as legitimate employers to lure software engineers, project managers and crypto professionals into remote technical interviews. During those sessions, candidates were asked to run test programs, share screens or install remote-access software that contained backdoors. Once the tools were installed, attackers gained control of machines and accessed cryptocurrency wallets and exchange accounts.

Sources tracking the activity attribute the campaign to groups tied to North Korea’s state-sponsored cyber program. The operation used cloned company pages, bogus recruiter profiles on professional networks and fake job listings to arrange interviews. Targets reported losses after attackers used stolen credentials to transfer assets or to authorize transactions on exchanges.

Researchers say operators focused on blockchain firms, decentralized finance projects and individual holders with large balances. In several incidents attackers prompted victims to open web-based wallets while sharing screens, captured seed phrases or approved transactions, and in other cases used remote-access tools to harvest keys, passwords and two-factor authentication tokens.

The interview sessions often featured realistic technical tests, whiteboard exercises and staged video calls. Attackers took steps to appear legitimate by using corporate logos, professional email signatures and follow-up messages from bogus HR contacts. After gaining access, funds were moved through multiple accounts and mixing services to obscure the trail before being cashed out.

A cybersecurity researcher familiar with the investigations described the tactic as “Using a recruitment process to build trust and then pivot to theft is an effective form of deception.” The researcher noted that candidates often lower their guard during technical assessments, which can allow attackers to obtain the access they need.

Law enforcement agencies in multiple countries have opened inquiries into the thefts. Private firms that track illicit crypto flows continue to monitor transfers tied to the campaign and to other North Korean cyber operations.

Security firms and investigators have advised organizations and candidates to require code tests run in isolated environments, prohibit screen-sharing that exposes private keys, verify recruiters through official company channels and use hardware wallets or other cold-storage options for significant holdings. Companies are also urged to verify the identity of external recruiters and applicants through multiple channels before conducting live technical assessments.

Investigations are ongoing.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author