BlockBeats News: On January 22, following the theft of over $2 billion from the cryptocurrency market in 2025, North Korean hackers have returned. A hacking group known as PurpleBravo has launched a large-scale fake recruitment campaign, targeting more than 3,100 internet addresses related to artificial intelligence, cryptocurrency, and financial services companies. Attackers impersonated recruiters or developers to lure job seekers into performing technical interview tasks, such as code reviews, cloning code repositories, or completing programming assignments, which allowed the execution of malicious code on corporate devices. To date, 20 organizations in South Asia, North America, Europe, the Middle East, and Central America have been confirmed as victims.
Researchers have found that North Korean hackers used fake Ukrainian identities as cover and deployed two remote access trojans, PylangGhost and GolangGhost, to steal browser credentials. Additionally, they weaponized Microsoft Visual Studio Code, implanting backdoors through malicious Git repositories.
