Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

North Korea-linked cyber activity has expanded beyond conventional hacking into a wider portfolio that includes cryptocurrency theft, social engineering, fake recruiting, fraudulent IT employment, data theft, and extortion. These tactics overlap; the public record does not show a clean shift in which one replaced another, or establish a single group responsible for every operation.

What has changed in North Korea-linked cyber activity?

The clearest change is the range of ways operators seek access and generate revenue. Some campaigns use social engineering to persuade a target to install a malicious application. Others turn job interviews and coding assignments into opportunities to run malicious code, or use fraudulent remote employment to gain continuing access to company systems. Cryptocurrency theft and revenue generation remain part of this picture.

The labels used by governments vary. A 2022 FBI, CISA, and Treasury advisory identified activity under names including Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. A 2026 multinational advisory calls the activity it describes WaterPlum and notes the alias Contagious Interview. Those labels should be understood as attributions used in particular advisories, not as proof that every name refers to one unified group or command structure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ODNI’s 2026 Annual Threat Assessment describes the broader capability this way: “North Korea’s cyber program is sophisticated and agile.” The sources document particular tactics and cases, not a comprehensive history of every North Korean operation.

How has the activity developed over time?

Period What government sources reported What the evidence establishes
At least 2020 through April 2022 A joint FBI, CISA, and Treasury advisory described cryptocurrency theft activity that had been conducted since at least 2020. Targets included exchanges, decentralized-finance protocols, play-to-earn games, trading firms, venture-capital funds, and large individual holders. The advisory described social engineering and trojanized cryptocurrency applications as ways to gain access and steal assets. It is evidence of activity in that period, not a claim that all operations used the same method.
September 2024 FBI/IC3 warned that actors researched cryptocurrency-sector targets, impersonated people or organizations, and used tailored job or investment scenarios and extended conversations to build trust. The FBI described human interaction as part of the path to malware delivery, alongside technical safeguards firms could use.
January 2025 The FBI warned that North Korean IT workers had used access at U.S.-based companies to take sensitive material, facilitate crime, and generate revenue. The reported behaviors included copying code, extortion, harvesting credentials and session cookies, and deception during interviews.
2025 estimate, published in 2026 ODNI assessed that North Korea’s cryptocurrency heists probably stole $2 billion in 2025. This is an intelligence-community estimate, not a verified transaction ledger or a court finding. ODNI said the money helps fund the regime, including strategic-weapons programs.
Approximately December 2025 through July 2026 A multinational advisory dated September 18, 2026, described WaterPlum actors posing as employers and recruiters, including those associated with AI, cryptocurrency, and NFT companies. The advisory reported at least 30,000 compromised devices in more than 100 countries, more than 7,000 cryptocurrency wallets with funds or credentials transferred, and at least 1.7 billion Japanese yen (approximately $10.71 million USD) in cryptocurrency exfiltrated. These are figures reported by the advisory, not independently verified totals.

How do fake job interviews become a cyberattack?

A recruiting conversation can provide both a convincing pretext and a route to execute malware. In the campaign described by the September 2026 multinational advisory, actors posed as employers or recruiters and used technical interviews and coding tasks to persuade software professionals to download packages or run code. A task that appears to be ordinary hiring work can therefore become the delivery mechanism for a malicious file.

The advisory names BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle as examples of malware associated with the activity it describes. That is not an exhaustive inventory of malware used by North Korea-linked actors.

  • Be wary when an unsolicited recruiter or employer asks you to download a package or execute code as part of an interview.
  • Verify the recruiter and role through a contact method you find independently, rather than relying only on details in the message.
  • Do not run untrusted code on a device or account that can reach company systems, repositories, credentials, or cryptocurrency assets.

These precautions address the risk described in the advisory; they do not imply that every unusual interview task is malicious.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does social engineering lead to cryptocurrency theft?

In the activity described by the 2022 joint FBI, CISA, and Treasury advisory, social engineering could persuade a target to download a trojanized cryptocurrency application. Malware could then help the operators access a system and steal cryptocurrency or expose private keys. The advisory described targets across the cryptocurrency ecosystem, from exchanges and decentralized-finance protocols to individual holders.

The FBI/IC3’s September 2024 alert added detail on how trust could be established: research on targets, individualized job or investment scenarios, impersonation, and prolonged conversations. As the FBI put it, “North Korean social engineering schemes are complex and elaborate, often compromising victims with sophisticated technical acumen.” The point is not that every intrusion follows this script, but that a technically capable attack can begin with a tailored human interaction.

What makes fraudulent IT employment a different kind of risk?

A malicious download may create a discrete point of entry. Fraudulent employment can instead give an actor access through a worker’s accounts, device, or assigned duties over time. The FBI’s January 2025 warning described remote IT workers using company access to copy repositories, take sensitive data, harvest credentials or session cookies, and extort employers. This combination can expose hiring and onboarding processes as well as technical systems.

The FBI noted that suspicious login patterns can include multiple logins to one account in a short period from different IP addresses and countries. Its January 2025 alert stated: “North Korean IT workers often have multiple logins into one account in a short period of time from various IP addresses, often associated with different countries.” A single unusual login is not proof of this activity, but repeated geographic and access anomalies merit investigation in context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Verify remote workers’ identities during hiring and employment; where appropriate, validate employment and education details with the institutions involved.
  • Limit accounts to the access needed for the job, and avoid unnecessary administrative privileges or remote-access tools.
  • Monitor for unusual logins, remote connections, browser-session activity, and unexpected copying or movement of code and data.
  • Scrutinize last-minute changes to onboarding details or payment arrangements.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does the financial evidence fit together?

The published figures come from different kinds of government reporting and should not be treated as interchangeable. ODNI’s estimate concerns likely cryptocurrency theft in 2025. The Justice Department’s 2025 update describes allegations in legal matters and ongoing tracing and forfeiture work.

Government report Figure reported How to interpret it
ODNI, 2026 Annual Threat Assessment North Korea’s cryptocurrency heists probably stole $2 billion in 2025. An intelligence-community assessment, with “probably” part of the stated qualification; not a final adjudication of individual transactions.
Multinational WaterPlum advisory, September 18, 2026 At least 30,000 devices in more than 100 countries; more than 7,000 wallets with funds or credentials transferred; at least 1.7 billion Japanese yen, approximately $10.71 million USD, in cryptocurrency exfiltrated during the campaign window described. Totals reported by the advisory for the activity it describes; not independently verified totals.
U.S. Department of Justice, 2025 update Allegations involving a fraudulent IT-worker scheme that obtained work at more than 64 U.S. companies and more than $943,069 in salary payments, most of which was sent overseas. Allegations described by DOJ, not a statement that every detail has been finally established in court.
U.S. Department of Justice, 2025 update Four alleged APT38-linked virtual-currency thefts in 2023, valued at approximately $37 million, $100 million, $138 million, and $107 million. DOJ described related tracing and forfeiture actions as ongoing. The reported values are tied to the alleged thefts; they are not final findings about recovered funds.

DOJ’s account of tracing efforts describes cryptocurrency moving through bridges, mixers, exchanges, and over-the-counter traders. A tracing or forfeiture action is distinct from a seizure and from a final judicial finding; the legal status of each case matters when describing what has been proved.

What should organizations do if they suspect an incident?

The FBI’s recommendations span hiring, access control, monitoring, and incident response. In a suspected compromise, preserve evidence while limiting further exposure:

  1. Disconnect an affected device from the internet. The FBI advises isolating it, while leaving it powered on so recoverable artifacts are not lost.
  2. Report the incident through IC3. The FBI advises organizations to contact law enforcement and discuss forensic options.
  3. Review access and activity. Check accounts, remote connections, browser sessions, repositories, and unusual data movement for indicators relevant to the incident.
  4. Reassess hiring and permissions. Apply identity verification and least privilege, and restrict unnecessary administrative rights and remote-access software.

Follow law enforcement’s direction on evidence preservation and any forensic examination. The FBI says private incident-response firms may be recommended in some situations; that is not an endorsement of a particular provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the public record does—and does not—show

Government reporting shows a widening set of access and monetization methods: social engineering and malicious applications, recruitment lures, fraudulent IT work, cryptocurrency theft, data theft, and extortion. It does not establish a complete organizational chart, prove that every named actor or campaign is interchangeable, or show that espionage has simply been replaced by crime. The more defensible conclusion is that these activities coexist in a cyber portfolio that can use both technical compromise and human trust to pursue access and revenue.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.