North Korean hackers pose as IT workers to infiltrate crypto projects and exchanges

來源 Cryptopolitan

North Korean hackers regularly apply to Binance. Investigators have also intercepted resources of hackers spinning up identities to apply to key IT jobs. 

The threat of DPRK hackers posing as IT workers is still active. Sources have discovered recent data on the techniques used to spin up fake identities and apply as IT workers. 

ZachXBT, known for tracking DPRK hackers, recently discovered information from one of the attacker’s devices. ZachXBT has often called out the risk of hiring DPRK workers, which leads to risks for smart contracts, multisig wallets, or compromised devices.

An unnamed source pointed to records of five DPRK hackers, spinning up 30 identities and applying to key IT tasks in crypto and other projects. 

The teams used fake locations, local names, and identities, overlapping with crypto-friendly countries like Ukraine and Estonia. 

North Korean IT workers scour job boards 

Leaked documents showed the tools and tracking used by the team, including attempts to build the fake identities. 

The hackers used shared documents, revealing a series of Upwork credit purchases. The finding coincides with reports of attempts to buy or rent Upwork accounts and bid on software jobs. Some of the most common jobs included various blockchain roles, smart contract engineering, as well as work on specific projects, including Polygon Labs.

Earlier reports showed that not all North Korean IT workers had hacking in mind or targeted crypto. Some of the workers had the task of earning from legitimate IT jobs, later handing over their pay to the North Korean regime. 

An escaped IT worker outlined the scheme, showing that the presence of DPRK IT workers was a constant threat to traditional companies and crypto teams. 

Binance filters out DPRK applications almost daily

Binance’s security officer Jimmy Su said the exchange is constantly filtering out candidates. DPRK hackers try to gain access to key crypto positions, and Binance has intercepted both through CV monitoring and at the interview stage. Crypto space also carries unofficial lists of known fake identities, using legitimate-looking LinkedIn accounts and social media profiles. 

In the past, Cryptopolitan reported cases where DPRK hackers built the key infrastructure for Web3 projects, leading to compromised smart contracts with known exploit backdoors. These hackers have affected multiple projects, from DeFi to Solana memes. Some of the teams also launched meme tokens as a way of laundering funds. 

In addition to public fake profiles, DPRK hackers also use infected code repos or malicious links to make users install malware. Techniques include fake job interviews with links to malware. DPRK hackers also pose as interviewers or project managers, setting up fake meetings with a fake download link.

In some cases, hackers have also proposed to Upwork users to connect to their computer remotely as a way to use new accounts without exposing their identity. Reports have it that some US-based persons agreed to the exchange, allowing the supposed IT workers access via AnyDesk. The hackers also used crypto payments through an intermediary Ethereum wallet, which has been linked to addresses used in large-scale hacks. 

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
金管會新規砍殺9%高利! 0056填息術大公開:3招避坑「假股息」、年賺12%攻略元大高股利(0056)作為市場標桿,其價值正被重新定義-配息不再是唯一指標,能否填息才是檢驗真金的試金石。
作者  投資-槓把子
8 月 08 日 週五
元大高股利(0056)作為市場標桿,其價值正被重新定義-配息不再是唯一指標,能否填息才是檢驗真金的試金石。
placeholder
川普放風:半導體關稅恐高達300%,台積電面臨巨大壓力未來兩週內,他打算宣布對進口半導體(也就是晶片)產品加徵新的關稅,而且稅率可能高得驚人——最高達到300%。在此之前,川普政府在本月剛將鋼鋁關稅提升到了50%,現在又把目標轉向了晶片產業,顯示出美國的貿易政策正在進一步升級。
作者  投資-槓把子
昨日 01: 30
未來兩週內,他打算宣布對進口半導體(也就是晶片)產品加徵新的關稅,而且稅率可能高得驚人——最高達到300%。在此之前,川普政府在本月剛將鋼鋁關稅提升到了50%,現在又把目標轉向了晶片產業,顯示出美國的貿易政策正在進一步升級。
placeholder
台玻(1802)爆量漲停,PCB上游玻纖布緊缺,惟三大風險不得不防!由於ABF載板、高階BT載板所需重要原料玻纖布的供應持續吃緊,加之輝達GB200、GB300出貨放量,引發上游關鍵材料供應緊張,台玻(1802)開盤半小時即爆出10萬張以上的大量,亮燈漲停、跨過37元,創2021年9月以來高價。不過,受到川普稱半導體關稅將徵收300%衝擊以及鮑威爾或將於傑克森霍爾(Jackson Hole)全球央行年會上「放鷹」,台灣加權指數以平盤作收,指數漲148.04點,收24482.52點,但後續風險不容忽視,投資者宜保持謹慎。
作者  Insights
18 小時前
由於ABF載板、高階BT載板所需重要原料玻纖布的供應持續吃緊,加之輝達GB200、GB300出貨放量,引發上游關鍵材料供應緊張,台玻(1802)開盤半小時即爆出10萬張以上的大量,亮燈漲停、跨過37元,創2021年9月以來高價。不過,受到川普稱半導體關稅將徵收300%衝擊以及鮑威爾或將於傑克森霍爾(Jackson Hole)全球央行年會上「放鷹」,台灣加權指數以平盤作收,指數漲148.04點,收24482.52點,但後續風險不容忽視,投資者宜保持謹慎。
placeholder
台股創歷史新高!專家警告:短線只能“做價差”,留意兩大反轉訊號一旦出現「量能萎縮至4000億以下」且「資金轉炒低價股」的跡象,即表示主力撤離、散戶接棒,台股走勢恐面臨重要轉折(北風北),高價股恐將停滯。
作者  投資-槓把子
2 小時前
一旦出現「量能萎縮至4000億以下」且「資金轉炒低價股」的跡象,即表示主力撤離、散戶接棒,台股走勢恐面臨重要轉折(北風北),高價股恐將停滯。
placeholder
育華工業宣布年底熄燈,瀧澤科技啟動週休三日,產業寒冬警報拉響?投資慧眼Insights-新台幣匯率強勢升值,加上美國祭出20%的對等關稅雙重夾擊,台灣出口導向的傳統產業壓力爆表!
作者  投資指南針
2 小時前
投資慧眼Insights-新台幣匯率強勢升值,加上美國祭出20%的對等關稅雙重夾擊,台灣出口導向的傳統產業壓力爆表!
goTop
quote