North Korean Hackers Infect Thousands of Devices and Steal Millions in Crypto
A joint investigation by law enforcement agencies in Australia, Germany, Japan, and the United States has uncovered a massive cybercrime scheme orchestrated by North Korean hackers. The attackers are using fake job openings to infect IT professionals' computers with malware, steal cryptocurrency, and harvest data for further attacks.
The campaign has compromised over 30,000 devices and more than 7,000 cryptocurrency wallets, resulting in estimated losses of at least $10.71 million. This amount is used to fund the North Korean regime.
The hackers pose as company recruiters and contact specialists with job offers. During the interview, they send a technical specification or code for testing that contains malware. Once opened, remote access tools and data-stealing programs are installed on the device, collecting logins and passwords, clipboard data, keystrokes, access to crypto wallets, and documents.
This scheme is part of a larger global operation worth over $500 million per year. North Korean IT specialists use stolen identity documents to fake identities when applying for jobs abroad, circumventing international sanctions. They also use 'laptop farms' with accomplices leaving devices in the US or Europe to simulate a local presence.