The FBI and Japan’s National Police Agency issue a joint warning about North Korea linked hackers running a massive device infection campaign.
Investigators say the hacking group infects more than 30,000 devices across over 100 countries as part of an ongoing operation targeting crypto workers.
The campaign specifically targets employees at cryptocurrency, artificial intelligence, and NFT firms by posing as legitimate recruiters offering attractive job opportunities.
Victims receive fake interview invitations and coding assignments that secretly install malware, granting hackers persistent access to company systems and personal devices.
Authorities report the hackers successfully steal funds from more than 7,000 individual crypto wallets during this extended and coordinated campaign.
Total losses linked to this specific operation reach approximately $10.71 million, according to figures shared by investigators tracking the group’s activity.
This tactic mirrors well documented North Korean cyber strategies. State linked groups routinely pose as recruiters on LinkedIn and other professional networks.
Previous campaigns used similar methods to breach wallet software companies and exchanges, sometimes resulting in losses reaching hundreds of millions of dollars.
Security researchers note that fake job offers remain one of the most effective social engineering tools used by North Korean hacking collectives.
The malware deployed often masquerades as pre-employment coding tests, tricking developers into running malicious scripts on machines with sensitive system access.
United Nations officials have previously stated that North Korea relies heavily on cryptocurrency theft to fund its sanctioned weapons and missile programs.
Crypto companies are urged to strengthen hiring verification processes and train staff to recognize suspicious recruitment outreach before it leads to a breach.

