Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
North Korean hacker group PurpleBravo has launched attacks on over 3,100 IPs in the AI and crypto industries

North Korean hacker group PurpleBravo has launched attacks on over 3,100 IPs in the AI and crypto industries

ForesightNewsForesightNews2026/01/22 11:00
Show original

Foresight News reported, according to monitoring by Insikt Group, that the North Korean state-sponsored hacker group PurpleBravo (overlapping with the "Contagious Interview" campaign) launched attacks on 3,136 unique IP addresses involved in AI, cryptocurrency, financial services, and IT development fields between August 2024 and September 2025. The group lured developers into executing malicious code on company devices by impersonating fake LinkedIn recruiters, conducting interview programming tests, and using malicious GitHub repositories.


PurpleBravo's toolkit includes the JavaScript information stealer BeaverTail, as well as the cross-platform remote access trojans PyLangGhost and GolangGhost, which are designed to steal browser credentials and cryptocurrency wallet information. Investigations revealed that the group manages its command and control servers via Astrill VPN and IP addresses located in China. Insikt Group emphasized that since the main targets are IT services and personnel outsourcing industries, such attacks could pose serious software supply chain risks to downstream clients.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!
© 2025 Bitget