CandyPulse

North Korean Hackers Linked to $10.7M Theft via Fake-Recruiter Scam

By CANDY Team · 2026-09-23 · News

Authorities have tied North Korean state-linked hackers to a fake-recruiter campaign that stole at least $10.7 million in crypto assets. The scheme reportedly used bogus job offers and recruiter outreach to trick crypto industry workers and developers into compromising their systems or wallets — a tactic that has become a recurring playbook for North Korea-linked threat actors targeting the crypto sector.

The theft surfaced alongside a separate warning from Binance to iPhone and iPad users, urging them to check whether they had installed an app called FomoPeek after security researchers flagged versions of it as malicious.

Why it matters: State-linked hacking groups continue to treat crypto firms and individual developers as high-value targets, using social engineering (fake jobs, fake recruiters) rather than pure technical exploits to get in the door. Anyone in the industry approached with unsolicited "job opportunities" that require installing software or sharing credentials should treat it as a red flag.

Source: Cointelegraph

More on CandyPulse

Meet SugarPen: The AI Writing Agent That Refuses to Make Things Up

What Everyone Gets Wrong About Crypto Volatility

The Quiet Comeback of 'Boring' Crypto — and Why It Might Define the Next Cycle

The Market Doesn't Reward the Best Technology — Here's What It Actually Rewards