Fake IT Interviews: How North Korea Stole Millions in Crypto

Fake Tech Interviews Linked to North Korean Crypto Theft Campaign

A North Korean state-backed hacking group infected more than 30,000 computers in at least 100 countries as part of a campaign that stole millions of dollars in cryptocurrency between late 2025 and July 2026.

Attackers Posed as Technology Recruiters

The campaign reportedly used fake job interviews to target technology professionals. Attackers presented the recruitment process as legitimate before directing candidates to download files or run software that contained malware.

Once installed, the malicious software could provide attackers with access to victims’ computers and potentially expose sensitive information, including credentials, private keys and other data linked to cryptocurrency accounts.

Global Reach

More than 30,000 computers across at least 100 countries were reportedly affected. The broad geographic scope reflects the use of online recruitment platforms and remote interview processes to reach potential victims in the technology sector.

The campaign operated from late 2025 through July 2026, according to the available information. The attackers allegedly used the stolen access and information to take millions of dollars in cryptocurrency.

Security Risks for Crypto Users

Cryptocurrency holders and technology workers remain frequent targets of malware campaigns because compromised devices can expose exchange accounts, digital wallets and authentication credentials. Fake employment opportunities can be especially effective because they often involve requests to install software, open documents or access unfamiliar websites.

Security specialists generally advise job candidates to verify recruiters and employers independently, avoid installing untrusted software during an interview process and use dedicated devices or accounts when handling sensitive cryptocurrency assets.

×