North Korean hackers make a comeback, attacking over 3,100 IP addresses using fake job interview scams

robot
Abstract generation in progress

On January 22, after stealing over $2 billion from the cryptocurrency market in 2025, North Korean hackers have made a comeback. The hacking group known as PurpleBravo launched a large-scale fake recruitment campaign, targeting over 3,100 internet addresses related to artificial intelligence, cryptocurrency, and financial services companies. The attackers impersonated recruiters or developers, tricking job seekers into performing technical interview tasks, including reviewing code, cloning code repositories, or completing programming assignments, thereby executing malicious code on corporate devices. Currently, 20 organizations from South Asia, North America, Europe, the Middle East, and Central America have been confirmed as victims. Researchers found that North Korean hackers used forged Ukrainian identities to conceal their activities and deployed two remote access Trojans, PylangGhost and GolangGhost, to steal browser credentials. Additionally, they developed weaponized Microsoft Visual Studio Code, implanting backdoors through malicious Git repositories.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)