星期三, 16 7 月, 2025
ZKE News
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoins
  • NFT News
  • Blockchain
  • Regulations
  • Scams
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoins
  • NFT News
  • Blockchain
  • Regulations
  • Scams
No Result
View All Result
ZKE News
No Result
View All Result

You’re Hired! North Korea’s new crypto scam starts with a job offer

by NZU
20 6 月, 2025
in Scams
0
You’re Hired! North Korea’s new crypto scam starts with a job offer

Related articles

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

11 7 月, 2025
Scam targets dormant Bitcoin wallets with fake legal notice

Scam targets dormant Bitcoin wallets with fake legal notice

8 7 月, 2025
Nemo

A new wave of cyberattacks shows the DPRK is exploiting the crypto industry’s recruitment funnel, using fake LinkedIn job offers, deep‑fake Zoom calls, and backdoored interview files to access Web3 developers’ wallets and repositories.

With seasoned developer talent already thinning and open‑source protocols increasingly reliant on individual contributors, the stakes have never been higher.

North Korean hackers developer infiltration

On 18 June , cybersecurity firm Huntress reported a campaign attributed to BlueNoroff, a notorious Lazarus Group subgroup targeting a developer at a major Web3 foundation.

The ruse began with a polished recruiter pitch on LinkedIn, followed by what appeared to be a Zoom interview with a senior executive. In reality, the video feed was a deep‑fake, and the “technical‑assessment” file the candidate was asked to run, `zoom_sdk_support.scpt`, deployed cross‑platform malware dubbed BeaverTail that can harvest seed phrases, crypto‑wallets, and GitHub credentials.

These tactics represent a sharp escalation. “In this new campaign, the threat‑actor group is using three front companies in the crypto consulting industry … to spread malware via ‘job‑interview lures,’” researchers at Silent Push wrote in April, referring to companies such as BlockNovas, SoftGlide, and Angeloper. All three maintained U.S. corporate registrations and LinkedIn job posts that easily passed HR sniff tests.

The FBI seized the BlockNovas domain in April . By then, multiple developers had reportedly sat through fake Zoom calls where they were urged to install custom apps or run scripts. Many complied.

These aren’t simple smash‑and‑grab scams but part of a well‑funded, state‑directed campaign. Since 2017, North Korean hacking groups have stolen over $1.5 billion in crypto, including the $620 million Ronin/Axie Infinity hack.

The stolen assets are routinely funneled through mixers such as Tornado Cash and Sinbad, laundering Pyongyang’s take and ultimately bankrolling its weapons programme, according to the U.S. Treasury.

“For years, North Korea has exploited global remote IT contracting and crypto ecosystems to evade U.S. sanctions and bankroll its weapons programs,” said Sue J. Bai of the DoJ’s National Security Division. On 16 June, her office announced the seizure of $7.74 million in crypto tied to the fake‑IT‑worker scheme.

Crypto developer focus

The targets are carefully selected. The open‑source nature of crypto protocols means that a single engineer, often pseudonymous and globally distributed, may hold commit privileges to critical infrastructure, from smart contracts to bridge protocols.

Electric Capital’s most recent publicly available Developer Report counted about 39,148 new active crypto developers, with total developers down roughly 7% year‑on‑year. Industry analysts say the supply of seasoned maintainers has only tightened, making each compromised developer disproportionately dangerous.

That imbalance is why the hiring pipeline itself has become a cybersecurity battleground. Once a front‑company recruiter gets past HR, engineers, eager for stability in a bearish market, may not spot the red flags in time. In several cases, the attackers even used Calendly links and Google Meet invites that silently redirected victims to attacker‑controlled Zoom look‑alike domains.

The malware stack is advanced and modular. Huntress and Unit 42 have catalogued BeaverTail, InvisibleFerret, and OtterCookie variants, all compiled with the Qt framework for cross‑platform compatibility. Once installed, the tools scrape browser extensions such as MetaMask and Phantom, exfiltrate `wallet.dat` files, and search for terms like “mnemonic” or “seed” in plaintext files.

Yet despite the technical sophistication, law‑enforcement pressure is mounting. The FBI’s domain seizures, the DoJ’s financial forfeitures, and Treasury sanctions on mixers have begun to raise the cost of doing business for Pyongyang’s hackers. The regime, however, remains adaptive.

Each new shell company, recruiter persona, or malware payload arrives wrapped in more convincing packaging. Thanks to generative‑AI tools, even the fake executives in live calls now look and move credibly. DeFi’s trustless systems still rely on a surprisingly small and vulnerable circle of trusted human maintainers.

North Korean crypto target onslaught

Recent CryptoSlate coverage paints a broader canvas of Pyongyang’s crypto onslaught. One year-end analysis found that North Korea-linked groups siphoned $1.34 billion from 47 hacks in 2024, which was a total of 61 % of all crypto stolen that year.

A big slice of that tally came from the $305 million breach of Japan’s DMM Bitcoin, which the FBI says started when a TraderTraitor operative posed as a LinkedIn recruiter and slipped a malicious “coding test” to a Ginco wallet engineer.

The same playbook escalated this February when the bureau attributed a record $1.5 billion Bybit exploit to Lazarus, noting the thieves had already laundered 100,000 ETH through THORChain within days.

North Korean operatives are impersonating venture capitalists, recruiters, and remote IT workers, using AI-generated profiles and deep-fake interviews, to earn salaries, exfiltrate source code, and extort firms in what Microsoft researchers call a “triple-threat” scheme.

In a world where jobs can be remote, trust is digital, and software runs the money, the subsequent state‑sponsored breach may begin not with an exploit but with a handshake.

Mentioned in this article
Latest North Korea Stories
Latest Alpha Market Report

Credit: Source link

Previous Post

OKB hits $54.7 after 42.4 mln token burn – Can it break through $56?

Next Post

Hong Kong Monetary Authority Reports Decrease in Composite Interest Rate for May 2025

Related Posts

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

11 7 月, 2025

The Beijing Internet...

Scam targets dormant Bitcoin wallets with fake legal notice

Scam targets dormant Bitcoin wallets with fake legal notice

8 7 月, 2025

Analysts at BitMEX R...

Crypto firms paid $2.7M monthly to North Korean workers

Crypto firms paid $2.7M monthly to North Korean workers

2 7 月, 2025

An on-chain investig...

Bybit and North Korean hackers headline $2.1 billion crypto hacks in H1

Bybit and North Korean hackers headline $2.1 billion crypto hacks in H1

27 6 月, 2025

The first half of 20...

ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

17 6 月, 2025

Investigators have l...

Load More

发表回复 取消回复

您的邮箱地址不会被公开。 必填项已用 * 标注

Can Solana (SOL) hit $184 after FTX, Alameda unstake $31 million?

Can Solana (SOL) hit $184 after FTX, Alameda unstake $31 million?

12 7 月, 2025
Crypto Hacker Who Drained $42,000,000 From GMX Goes White Hat, Returns Funds in Exchange for $5,000,000 Bounty

Crypto Hacker Who Drained $42,000,000 From GMX Goes White Hat, Returns Funds in Exchange for $5,000,000 Bounty

13 7 月, 2025
Top 5 Presales to Explode During This Bull Run as Bitcoin Reaches $118K ATH, More Solana Treasuries Announced, and More…

Top 5 Presales to Explode During This Bull Run as Bitcoin Reaches $118K ATH, More Solana Treasuries Announced, and More…

11 7 月, 2025
Ethereum Reclaims NFT Market Dominance – Rises +30% In Sales

Ethereum Reclaims NFT Market Dominance – Rises +30% In Sales

11 7 月, 2025
What’s Driving Crypto in 2025? 99Bitcoins Releases Q2 Report

What’s Driving Crypto in 2025? 99Bitcoins Releases Q2 Report

12 7 月, 2025

ZKE NEWS

ZKE News is an online news source that provides the latest updates on crypto news, including Bitcoin, Altcoin, Blockchain, NFT news, crypto regulation, scams, and much more.

Categories

  • Altcoins
  • Bitcoin
  • Blockchain
  • Crypto News
  • NFT News
  • Regulations
  • Scams

Tags

Altcoins Bitcoin Blockchain Crypto News NFT News Regulations Scams
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2023 - news.zke.us - All Rights Reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoins
  • NFT News
  • Blockchain
  • Regulations
  • Scams

© 2018 JNews by Jegtheme.

  • bitcoinBitcoin(BTC)$57,792.00-0.07%
  • ethereumEthereum(ETH)$3,102.631.60%
  • tetherTether(USDT)$1.00-0.06%
  • binancecoinBNB(BNB)$522.791.33%
  • solanaSolana(SOL)$141.960.36%
  • usd-coinUSDC(USDC)$1.000.04%
  • staked-etherLido Staked Ether(STETH)$3,109.901.85%
  • rippleXRP(XRP)$0.4379300.51%
  • ToncoinToncoin(TON)$7.21-1.35%
  • dogecoinDogecoin(DOGE)$0.1074050.22%
  • cardanoCardano(ADA)$0.3837042.22%
  • tronTRON(TRX)$0.1312550.99%
  • avalanche-2Avalanche(AVAX)$25.71-1.89%
  • shiba-inuShiba Inu(SHIB)$0.0000160.46%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$57,635.00-0.37%
  • polkadotPolkadot(DOT)$6.120.47%
  • chainlinkChainlink(LINK)$12.75-0.39%
  • bitcoin-cashBitcoin Cash(BCH)$337.722.22%
  • uniswapUniswap(UNI)$8.060.22%
  • leo-tokenLEO Token(LEO)$5.82-0.47%
  • daiDai(DAI)$1.00-0.17%
  • nearNEAR Protocol(NEAR)$4.601.94%
  • litecoinLitecoin(LTC)$66.672.01%
  • matic-networkPolygon(MATIC)$0.512.19%
  • Wrapped eETHWrapped eETH(WEETH)$3,226.781.47%
  • KaspaKaspa(KAS)$0.170006-0.24%
  • PepePepe(PEPE)$0.0000091.70%
  • Ethena USDeEthena USDe(USDE)$1.000.08%
  • internet-computerInternet Computer(ICP)$7.18-0.70%
  • Renzo Restaked ETHRenzo Restaked ETH(EZETH)$3,141.781.50%
  • ethereum-classicEthereum Classic(ETC)$20.921.45%
  • fetch-aiArtificial Superintelligence Alliance(FET)$1.19-0.56%
  • moneroMonero(XMR)$156.200.91%
  • AptosAptos(APT)$6.111.91%
  • stellarStellar(XLM)$0.087154-0.62%
  • render-tokenRender(RNDR)$6.491.31%
  • hedera-hashgraphHedera(HBAR)$0.065939-3.04%
  • cosmosCosmos Hub(ATOM)$6.031.74%
  • ArbitrumArbitrum(ARB)$0.711.89%
  • crypto-com-chainCronos(CRO)$0.084440-1.84%
  • filecoinFilecoin(FIL)$3.961.20%
  • blockstackStacks(STX)$1.5311.41%
  • MantleMantle(MNT)$0.695.02%
  • okbOKB(OKB)$36.790.61%
  • makerMaker(MKR)$2,306.631.51%
  • vechainVeChain(VET)$0.0258250.28%
  • injective-protocolInjective(INJ)$20.54-0.30%
  • First Digital USDFirst Digital USD(FDUSD)$1.00-0.03%
  • immutable-xImmutable(IMX)$1.25-1.34%
  • optimismOptimism(OP)$1.664.89%
  • BittensorBittensor(TAO)$260.472.91%
  • SuiSui(SUI)$0.73-1.44%
  • the-graphThe Graph(GRT)$0.1857292.27%
  • BonkBonk(BONK)$0.0000263.40%
  • Rocket Pool ETHRocket Pool ETH(RETH)$3,463.321.46%
  • NotcoinNotcoin(NOT)$0.015896-3.20%
  • dogwifhatdogwifhat(WIF)$1.62-3.51%
  • Mantle Staked EtherMantle Staked Ether(METH)$3,217.261.40%
  • lido-daoLido DAO(LDO)$1.675.99%
  • arweaveArweave(AR)$22.490.58%
  • Bitget TokenBitget Token(BGB)$1.040.87%
  • FLOKIFLOKI(FLOKI)$0.0001493.91%
  • OndoOndo(ONDO)$0.984.71%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$9.570.50%
  • theta-tokenTheta Network(THETA)$1.361.96%
  • CelestiaCelestia(TIA)$6.80-4.62%
  • aaveAave(AAVE)$90.175.14%
  • fantomFantom(FTM)$0.4687043.51%
  • thorchainTHORChain(RUNE)$3.612.50%
  • jasmycoinJasmyCoin(JASMY)$0.0247126.62%
  • BrettBrett(BRETT)$0.118640-0.80%
  • algorandAlgorand(ALGO)$0.138571-0.33%
  • ether.fi Staked ETHether.fi Staked ETH(EETH)$3,090.241.21%
  • Pyth NetworkPyth Network(PYTH)$0.3017931.24%
  • JupiterJupiter(JUP)$0.78-1.73%
  • quant-networkQuant(QNT)$70.02-1.87%
  • elrond-erd-2MultiversX(EGLD)$37.221.39%
  • SeiSei(SEI)$0.328578-3.83%
  • CoreCore(CORE)$1.103.06%
  • gatechain-tokenGate(GT)$6.941.56%
  • ethereum-name-serviceEthereum Name Service(ENS)$27.130.86%
  • akash-networkAkash Network(AKT)$3.54-0.39%
  • kucoin-sharesKuCoin(KCS)$8.94-1.67%
  • FlareFlare(FLR)$0.019127-1.31%
  • flowFlow(FLOW)$0.551.29%
  • dYdXdYdX(DYDX)$1.321.96%
  • mantra-daoMANTRA(OM)$0.960.88%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$3,139.661.41%
  • axie-infinityAxie Infinity(AXS)$5.361.33%
  • galaGALA(GALA)$0.021604-0.81%
  • eosEOS(EOS)$0.520.36%
  • Tokenize XchangeTokenize Xchange(TKX)$9.640.57%
  • StarknetStarknet(STRK)$0.59-0.68%
  • bittorrentBitTorrent(BTT)$0.0000011.27%
  • msolMarinade Staked SOL(MSOL)$169.76-0.40%
  • BeamBeam(BEAM)$0.0148692.24%
  • FasttokenFasttoken(FTN)$2.340.62%
  • bitcoin-cash-svBitcoin SV(BSV)$38.061.96%
  • usddUSDD(USDD)$1.000.40%
  • tezosTezos(XTZ)$0.74-0.96%