North Korean hackers pose as IT workers to infiltrate crypto projects and exchanges

来源 Cryptopolitan

North Korean hackers regularly apply to Binance. Investigators have also intercepted resources of hackers spinning up identities to apply to key IT jobs. 

The threat of DPRK hackers posing as IT workers is still active. Sources have discovered recent data on the techniques used to spin up fake identities and apply as IT workers. 

ZachXBT, known for tracking DPRK hackers, recently discovered information from one of the attacker’s devices. ZachXBT has often called out the risk of hiring DPRK workers, which leads to risks for smart contracts, multisig wallets, or compromised devices.

An unnamed source pointed to records of five DPRK hackers, spinning up 30 identities and applying to key IT tasks in crypto and other projects. 

The teams used fake locations, local names, and identities, overlapping with crypto-friendly countries like Ukraine and Estonia. 

North Korean IT workers scour job boards 

Leaked documents showed the tools and tracking used by the team, including attempts to build the fake identities. 

The hackers used shared documents, revealing a series of Upwork credit purchases. The finding coincides with reports of attempts to buy or rent Upwork accounts and bid on software jobs. Some of the most common jobs included various blockchain roles, smart contract engineering, as well as work on specific projects, including Polygon Labs.

Earlier reports showed that not all North Korean IT workers had hacking in mind or targeted crypto. Some of the workers had the task of earning from legitimate IT jobs, later handing over their pay to the North Korean regime. 

An escaped IT worker outlined the scheme, showing that the presence of DPRK IT workers was a constant threat to traditional companies and crypto teams. 

Binance filters out DPRK applications almost daily

Binance’s security officer Jimmy Su said the exchange is constantly filtering out candidates. DPRK hackers try to gain access to key crypto positions, and Binance has intercepted both through CV monitoring and at the interview stage. Crypto space also carries unofficial lists of known fake identities, using legitimate-looking LinkedIn accounts and social media profiles. 

In the past, Cryptopolitan reported cases where DPRK hackers built the key infrastructure for Web3 projects, leading to compromised smart contracts with known exploit backdoors. These hackers have affected multiple projects, from DeFi to Solana memes. Some of the teams also launched meme tokens as a way of laundering funds. 

In addition to public fake profiles, DPRK hackers also use infected code repos or malicious links to make users install malware. Techniques include fake job interviews with links to malware. DPRK hackers also pose as interviewers or project managers, setting up fake meetings with a fake download link.

In some cases, hackers have also proposed to Upwork users to connect to their computer remotely as a way to use new accounts without exposing their identity. Reports have it that some US-based persons agreed to the exchange, allowing the supposed IT workers access via AnyDesk. The hackers also used crypto payments through an intermediary Ethereum wallet, which has been linked to addresses used in large-scale hacks. 

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
2025年最值得关注的芯片股?美银推荐这六只股票报告指出,尽管半导体行业销售额预计将在2025年增长15%至7250亿美元,显示出强劲的增长势头,但这一增速相较于今年的20%将有所放缓。具体来看,美国银行预计2025年内存销售额增速将从2024年同比增长79%降至增长20%,而不包含内存的核心半导体预计将增长13%。
作者  Investing.com
2024 年 12 月 18 日
报告指出,尽管半导体行业销售额预计将在2025年增长15%至7250亿美元,显示出强劲的增长势头,但这一增速相较于今年的20%将有所放缓。具体来看,美国银行预计2025年内存销售额增速将从2024年同比增长79%降至增长20%,而不包含内存的核心半导体预计将增长13%。
placeholder
净利润翻倍但股价狂泻,亚马逊Q4财报“罪不至此”?TradingKey - 美国科技巨头亚马逊Amazon(AMZN.US)于2月7日周四盘后公布了喜忧参半的2024年第四季业绩。营收和盈利超预期,但财测逊色、资本支出飙高,重挫盘后股价一度跌逾7%。亚马逊这份成绩单亮点不少,比如削减成本措施奏效、净利润几乎翻倍增长、云计算部门连续三个季度保持19%的增长率、电子商务业务在假日季表现强劲等。然而,投资人尤其关注的AI增长前景和资本支出令人唏嘘:一边
作者  TradingKey
2 月 07 日 周五
TradingKey - 美国科技巨头亚马逊Amazon(AMZN.US)于2月7日周四盘后公布了喜忧参半的2024年第四季业绩。营收和盈利超预期,但财测逊色、资本支出飙高,重挫盘后股价一度跌逾7%。亚马逊这份成绩单亮点不少,比如削减成本措施奏效、净利润几乎翻倍增长、云计算部门连续三个季度保持19%的增长率、电子商务业务在假日季表现强劲等。然而,投资人尤其关注的AI增长前景和资本支出令人唏嘘:一边
placeholder
8.18精选策略分享:比特币、以太币、WTI原油、联合健康(UNH)技术分析本周五(8月22日)鲍威尔出席杰克森霍尔(Jackson Hole)全球央行年会,市场关注鲍威尔是否会借此机会反驳当前过高的降息预期。美联储正陷入两难困境。一方面,关税措施导致的生产者物价指数(PPI)超预期上涨,预示着输入性通胀风险正在累积;另一方面,就业市场降温和制造业低迷又增加了经济下行压力。此外,美联储公布7月货币政策会议纪要、美俄乌三方会晤有望举行同样值得关注。
作者  Insights
23 小时前
本周五(8月22日)鲍威尔出席杰克森霍尔(Jackson Hole)全球央行年会,市场关注鲍威尔是否会借此机会反驳当前过高的降息预期。美联储正陷入两难困境。一方面,关税措施导致的生产者物价指数(PPI)超预期上涨,预示着输入性通胀风险正在累积;另一方面,就业市场降温和制造业低迷又增加了经济下行压力。此外,美联储公布7月货币政策会议纪要、美俄乌三方会晤有望举行同样值得关注。
placeholder
比特币回调跌破11.5万美元!三季度魔咒再现?未来走势如何?比特币(BTC)跌超2%,破11.5万关口,报114955美元。以太币(ETH)跌超4%,报4233美元。
作者  Alison Ho
20 小时前
比特币(BTC)跌超2%,破11.5万关口,报114955美元。以太币(ETH)跌超4%,报4233美元。
placeholder
8月19日财经早餐:特朗普中断会议致电普京,美元、美债收益率走高,黄金创近三周新低!据德国媒体称,特朗普在与欧洲领导人会晤中途,曾中断多边会议并致电普京。美国将为乌克兰提供安全保障,并希望最终能促成与俄总统普京的三边会谈。美企业绩期已近尾声,市场本周焦点在于几家美国零售商(沃尔玛、家得宝和Target等)的业绩表现,其业绩被视为观测美国消费者韧性的关键窗口。另外,美联储主席鲍威尔本周稍后将于堪萨斯联储银行举办的杰克森霍尔(Jackson Hole)全球央行年会上发表演说。
作者  Insights
4 小时前
据德国媒体称,特朗普在与欧洲领导人会晤中途,曾中断多边会议并致电普京。美国将为乌克兰提供安全保障,并希望最终能促成与俄总统普京的三边会谈。美企业绩期已近尾声,市场本周焦点在于几家美国零售商(沃尔玛、家得宝和Target等)的业绩表现,其业绩被视为观测美国消费者韧性的关键窗口。另外,美联储主席鲍威尔本周稍后将于堪萨斯联储银行举办的杰克森霍尔(Jackson Hole)全球央行年会上发表演说。
goTop
quote