← Back to Crime & Security

North Korean Hackers Steal $10.7 Million in Cryptocurrency via Global Campaign

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SEOUL — North Korean state-sponsored cyber threat actors have executed a massive global campaign that compromised at least 30,000 devices across more than 100 countries, resulting in the theft of $10.71 million from over 7,000 cryptocurrency wallets. The operation, identified by cybersecurity researchers as the "Contagious Interview" campaign, marks one of the most significant financial cyber heists attributed to the regime in recent years.

The attack vector targeted users primarily in the United States, Japan, Australia, and Germany, though infections were detected worldwide. Threat groups operating under aliases such as WaterPlum and PurpleBravo deployed sophisticated malware designed to infiltrate personal computers and mobile devices. Once inside a network, the malicious software scanned for cryptocurrency wallet credentials and private keys, exfiltrating funds before victims could detect the intrusion.

The campaign was uncovered on September 22, 2026, following a surge in unauthorized transactions across major blockchain networks. Security firms analyzing the breach determined that the attackers utilized social engineering tactics disguised as professional interviews to trick users into downloading infected files. This method allowed the threat actors to bypass standard security protocols and gain administrative access to victim systems.

The financial impact of the operation is substantial, with stolen assets moving rapidly through a series of digital transactions designed to obscure their origin. Analysts note that the scale of the theft suggests a coordinated effort to generate illicit revenue for the North Korean regime, which relies heavily on cybercrime to circumvent international economic sanctions. The funds are believed to be intended for state projects and military development.

Cybersecurity agencies in affected nations have issued urgent alerts to financial institutions and technology companies, urging them to monitor for similar indicators of compromise. While the specific mechanisms used to launder the stolen cryptocurrency remain under investigation, experts warn that the techniques employed in the Contagious Interview campaign may be adapted for future attacks against other sectors.

The North Korean government has not officially commented on the operation. However, historical patterns indicate that Pyongyang often denies involvement in such activities while continuing to leverage its cyber capabilities for state-sponsored espionage and financial gain. As of now, authorities have not identified a single point of failure that could prevent similar campaigns from recurring.

Questions remain regarding the full extent of the data exfiltration beyond cryptocurrency credentials. Investigators are currently assessing whether sensitive personal information or corporate secrets were also stolen during the intrusion. With the threat actors remaining active and capable of deploying new variants of their malware, the risk of further financial loss persists for individuals and organizations globally.

Discussion

0 / 2000