North Korea's Fake Job Interviews Drained $11M From 7,000 Crypto Wallets
A North Korean-linked crew posing as recruiters has compromised crypto and Web3 developers worldwide, stealing credentials or funds from more than 7,000 wallets and moving about $10.71 million to Pyongyang. Jointly identified by agencies in Japan, the U.S., Australia, and Germany, the group infected at least 30,000 devices in over 100 countries and used fake AI, crypto, and NFT job offers to deliver malware through coding tests and developer downloads. Investigators link the activity to North Korea’s 313 General Bureau and say it overlaps with remote IT worker operations, including shared infrastructure and laptop farms. Tactics included AI face-swapping in interviews, language tools, and malware such as BeaverTail, InvisibleFerret, and StoatWaffle. Authorities also dismantled a Japanese laptop farm and highlighted common warning signs like remote-only interviews, crypto pay requests, and suspiciously broad résumés.
