North Korea–Tied Operators Sustain Aggressive Crypto Targeting Campaign

February 21, 2026, marked one year since North Korean (DPRK) hackers stole approximately $1.46 billion in cryptoassets from Dubai-based exchange Bybit in the largest confirmed crypto theft on record.

Elliptic first attributed the attack to DPRK actors, an assessment later confirmed by the FBI. The group employed novel laundering tactics, including the use of refund addresses, worthless tokens, and diversification across mixing services.

By August 2025, over $1 billion had been laundered, much through suspected Chinese OTC services. Today, most funds are processed, but the Bybit hack marked an escalation, not an end, to DPRK’s crypto theft operations.

DPRK hackers stole a record $2 billion in cryptoassets throughout 2025, pushing their cumulative total past $6 billion. Analysts believe these funds finance North Korea’s nuclear and missile programs.

Activity accelerated in 2026, with Elliptic recording twice as many exploits in January as in the prior year.

Social engineering is the primary attack vector across these incidents, despite the technical exploits that follow. Operatives craft convincing personas and pretexts, likely enhanced by AI, to overcome language barriers and improve deception.

Example of a Zoom error screen as presented to a victim (Source: elliptic)
Example of a Zoom error screen as presented to a victim (Source: elliptic)

DangerousPassword, Contagious Interview, and IT Infiltration Tactics

Two ongoing campaigns, DangerousPassword and Contagious Interview, have netted $37.5 million since January 1, 2026.

DangerousPassword hijacks compromised social media accounts to contact targets, often citing shared connections, such as past conferences.

Victims join video calls on Zoom or Microsoft Teams, where fake audio errors prompt them to run command-line code installing malware. This malware hunts private keys, seed phrases, and passwords, enabling further account takeovers.

Contagious Interview fabricates job offers, luring targets into “technical tests” via malware-laced code repositories on trusted platforms. Execution deploys similar key-stealing tools.

An example of a Contagious Interview message (Source: elliptic)
An example of a Contagious Interview message (Source: elliptic)

Both campaigns risk compromising the organization if victims use employer devices. Beyond these, DPRK IT workers infiltrate crypto projects patiently. They use fake identities, cloned accounts, rented laptops for location spoofing, and even refer to accomplices.

Salaries provide direct revenue, but the real goal often involves backdoors, persistent access, or developer machine compromises in remote-first environments.

The Tenexium incident highlights this evolution. On January 1, 2026, Tenexium.io a self-described decentralized margin trading protocol in the Bittensor (TAO) ecosystem went offline amid $2.5 million liquidity drains from its treasury.

Registered in September 2025, the project showed no activity after December 31. Reports flagged DPRK-linked contributors, with blockchain analysis revealing laundering patterns matching known DPRK exploits, including cross-chain overlaps and centralized cashouts.

While not fully proven as a DPRK front from inception, evidence suggests operatives may now build fake projects to siphon funds, shifting from infiltration to creation.

This sustained campaign demands vigilance. DPRK tactics are becoming more sophisticated, blending AI-enhanced phishing, malware, and insider threats.

IncidentDateStolen AmountKey TacticSource
Bybit HackFeb 2025$1.46BSocial Engineering + ExploitElliptic, FBI
2025 TotalJan-Dec 2025$2BMixed (Social Eng., IT Infil.)Elliptic
TenexiumJan 1, 2026$2.5MSuspected Fake ProjectX Report
DangerousPassword + Contagious InterviewJan 2026$37.5MSocial EngineeringElliptic Research

Crypto firms must screen for social engineering red flags like unsolicited calls or repo tests vet remote hires rigorously, and use blockchain analytics across 60+ chains to trace tainted funds. Elliptic’s tools, including Investigator for laundering visualization, help block DPRK-linked assets.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories