North Korean hackers compromised 1,640 companies across 57 countries via fake job interviews, with focus on cryptocurrency wallet theft and server access.
Regulation & Gov ·
A cybersecurity researcher at Kumio discovered that North Korean threat actors have targeted 1,640 organizations across 57 countries by posing as recruiters in fake job interview schemes. According to reporting by WIRED, the researcher gained 22 months of access to the attackers' infrastructure, revealing that between 700 and 800 of those companies experienced severe compromise—yielding privileges including server root access, AWS credentials, and cryptocurrency wallet authentication materials.
The campaign demonstrates a concentrated effort to steal digital assets, with attackers exploiting weak credential management among third-party vendors to expand their foothold within target networks. The use of employment-based social engineering proved effective at gaining initial access to organizations across multiple geographies and sectors.
It remains unclear how many of the affected firms have been notified, whether cryptocurrency losses have been quantified, or what remediation steps have been taken by compromised organizations. The scope and methods suggest ongoing operational capability, though no detail has emerged on current threat level or timeline of the most recent intrusions.