Live
eineurope/
Home/Global/Topic · North Korean-linked job scam steals crypto credentials
Global4d ago

North Korean-linked job scam steals crypto credentials

A sophisticated North Korean-linked job interview scam used deepfakes and malicious code to steal passwords and crypto wallet credentials from a developer.

Sources
1 verified
Location
Updated
Friday, 24 April 2026 at 05:59 UTC
No media · text-only dispatch
Synthesis · 1 sources
A Serbian web developer was targeted by a sophisticated recruitment scam posing as a blockchain firm called Genusix Labs. The multi-stage attack featured convincing deepfake actors on Zoom calls and a malicious coding test that deployed a backdoor, exfiltrating 634 Chrome passwords, macOS keychain data, and MetaMask wallet credentials within 56 seconds. Blockchain intelligence firm zeroShadow attributes the campaign to North Korean state-linked actors, noting tactical and code overlap with a prior $40 million cryptocurrency heist.
e/eineurope · topic · T-05745