Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ethereum outperforms Bitcoin amid wave of institutional investment

    August 6, 2025

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » North Korean IT workers are using remote jobs to infiltrate crypto companies: report

    North Korean IT workers are using remote jobs to infiltrate crypto companies: report

    Isabella TaylorBy Isabella TaylorAugust 5, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    North Korean IT workers are using fake identities to infiltrate crypto firms and steal millions worth of digital assets through remote job scams, cybersecurity researchers at Google Cloud and Wiz have warned.

    Summary

    • North Korean threat actor UNC4899 operatives are increasingly targeting crypto companies.
    • Both Google Cloud and AWS environments have been exploited by the group in multi-million dollar crypto thefts.

    Separate reports published by the firms have tracked UNC4899, also known as TraderTraitor, a North Korean threat group tied to the country’s military intelligence.

    According to Google Cloud’s H2 2025 Cloud Threat Horizons Report, UNC4899 operates under the Reconnaissance General Bureau, North Korea’s main foreign intelligence agency.

    The group has remained active since at least 2020, focusing on the blockchain and cryptocurrency sectors while leveraging advanced social engineering tactics and cloud-specific attack techniques.

    How did UNC4899 infiltrate cloud environments?

    Google described two separate incidents in which UNC4899 compromised employees at different organizations—one using Google Cloud, the other using AWS. In both cases, the hackers posed as freelance job recruiters and approached employees over LinkedIn or Telegram. 

    Once contact was established, they convinced victims to execute malicious Docker containers on their workstations, launching downloaders and backdoors that created links to attacker-controlled infrastructure.

    Within days, the group moved laterally through internal networks, collected credentials, and identified infrastructure used to handle crypto transactions.

    In one case, UNC4899 was able to disable multi-factor authentication on a privileged Google Cloud account to access wallet-related services. After stealing crypto worth several million dollars, they re-enabled MFA to evade detection.

    In a separate AWS-related incident, the attackers used stolen long-term access keys but faced restrictions due to the victim’s enforced use of temporary credentials and MFA policies. They bypassed these defenses by stealing session cookies, which allowed them to manipulate JavaScript files stored in AWS S3 buckets. 

    These files were altered to redirect crypto wallet interactions to addresses controlled by the attackers, leading to another multimillion-dollar theft.

    A massive operation

    Cloud security firm Wiz also analyzed UNC4899 and published separate findings that align with Google’s.

    Experts at Wiz noted that the group has gone by multiple aliases, including Jade Sleet, Slow Pisces, and TraderTraitor, with each referring to a broader set of tactics used by different North Korean state-backed entities such as Lazarus Group, BlueNoroff, and APT38.

    UNC4899 had been active since 2020, but it wasn’t until 2023 that fake job offers became a central tactic, especially targeting employees at crypto exchanges, the firm said in a recent report.

    Among the most high-profile breaches attributed to the group are the $305 million hack of Japan’s DMM Bitcoin and the $1.5 billion Bybit breach in late 2024. 

    Wiz warned that cloud infrastructure remains a consistent point of entry or exploitation in these attacks, as many crypto firms operate in cloud-first environments with limited on-premise defenses.

    Millions in crypto lost

    Estimates of the financial damage vary but remain consistently high. According to Google and Wiz, UNC4899 alone has stolen multiple millions of dollars in each incident, while broader figures compiled by private researchers and government agencies point to even larger losses.

    A 2024 report from blockchain analytics firm Chainalysis found that North Korean hackers stole $1.34 billion in crypto that year alone. More recently, researchers at Wiz estimated that North Korea-linked threat actors have siphoned off $1.6 billion in digital assets in 2025 as of mid-year.

    Separately, independent blockchain investigator ZachXBT has estimated that between 345 and 920 North Korean operatives may have infiltrated jobs in the crypto industry, collectively receiving over $16 million in salaries since the start of 2025.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Isabella Taylor

    Related Posts

    Ethereum outperforms Bitcoin amid wave of institutional investment

    August 6, 2025

    Pepe poised for reversal, key support holds as bulls eye swing high

    August 6, 2025

    TAO Synergies ramps up Bittensor holdings, now holds over 42,000 TAO

    August 6, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Ethereum outperforms Bitcoin amid wave of institutional investment

    Crypto August 6, 2025

    After months of underperformance, Ethereum is starting to turn around on institutional interest. Summary Ethereum…

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025

    Pepe poised for reversal, key support holds as bulls eye swing high

    August 6, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    Imagen Network Integrates Grok Tools to Optimize Discovery Within Decentralized Networks

    August 6, 2025

    AGII Expands Adaptive Risk Detection Models for Safer Web3 Infrastructure

    August 6, 2025

    Imagen Network (IMAGE) Introduces Smart Community Hubs for Decentralized Social Collaboration

    August 5, 2025

    AGII Adds Predictive Workflow Analytics to Improve Automated Smart Contract Handling

    August 4, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    Pi Coin slumps amid renewed migration activity on Pi Network

    June 7, 2025

    Atua AI Expands XRP Cryptocurrency Capabilities to Accelerate Decentralized Financial Automation

    June 8, 2025

    Atua AI Expands XRP Cryptocurrency Capabilities to Accelerate Decentralized Financial Automation

    June 8, 2025

    Ethereum outperforms Bitcoin amid wave of institutional investment

    August 6, 2025

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    Imagen Network Integrates Grok Tools to Optimize Discovery Within Decentralized Networks

    August 6, 20250 Views

    AGII Expands Adaptive Risk Detection Models for Safer Web3 Infrastructure

    August 6, 20250 Views

    Imagen Network (IMAGE) Introduces Smart Community Hubs for Decentralized Social Collaboration

    August 5, 20250 Views

    AGII Adds Predictive Workflow Analytics to Improve Automated Smart Contract Handling

    August 4, 20250 Views
    Don't Miss

    Ethereum outperforms Bitcoin amid wave of institutional investment

    Crypto August 6, 2025

    After months of underperformance, Ethereum is starting to turn around on institutional interest. Summary Ethereum…

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025

    Pepe poised for reversal, key support holds as bulls eye swing high

    August 6, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    ProfitFarmers Review – Is it Legit? July 2025

    July 7, 20251 Views

    Ethereum outperforms Bitcoin amid wave of institutional investment

    August 6, 20250 Views

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 20250 Views

    Liberland urgently wants a market maker for its LLM token

    August 6, 20250 Views
    Don't Miss

    Ethereum outperforms Bitcoin amid wave of institutional investment

    Crypto August 6, 2025

    After months of underperformance, Ethereum is starting to turn around on institutional interest. Summary Ethereum…

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025

    Pepe poised for reversal, key support holds as bulls eye swing high

    August 6, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Ethereum outperforms Bitcoin amid wave of institutional investment

    August 6, 2025

    CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading

    August 6, 2025

    Liberland urgently wants a market maker for its LLM token

    August 6, 2025
    Recent Posts
    • Ethereum outperforms Bitcoin amid wave of institutional investment
    • CFTC Launches ‘Crypto Sprint’ Initiative, Seeks Public Input on Spot Digital Asset Trading
    • Liberland urgently wants a market maker for its LLM token
    • Pepe poised for reversal, key support holds as bulls eye swing high
    • CHART: Stablecoins are growing fast since the GENIUS Act
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.