North Korean hackers used shadow IT workers to carry out crypto heists

on

|

views

and

comments


Upland: Berlin Is Here!

North Korea has built a shadow workforce consisting of thousands of IT workers, according to U.S. officials.

This shadow workforce is linked with North Korea’s cybercrime operations and is used to carry out massive crypto hacks, The Wall Street Journal reported on June 11.

For instance, these shadow workers targeted a Sky Mavis engineer last year, posing as a recruiter on LinkedIn. After a phone conversation, the shadow worker gave him a document to review as part of the recruitment process. The document contained malicious code that allowed the North Korean hackers to break into Sky Mavis and steal over $600 million in the Ronin bridge hack.

These workers, spread across countries like Russia and China, earn as much as $300,000 per year doing mundane technology work. They have previously posed as Canadian IT workers, government officials, and freelance Japanese blockchain developers, the report said. The workers pose as potential recruiters or employees, conducting video interviews, as per the report.

To infiltrate crypto firms, the North Korean hackers hire Western “front people,” the report noted. These front people, or actors, sit through the interviews to get hired by crypto firms, which have no idea about their ties to the hackers. Once hired, they make small changes to the products to make them vulnerable, and the hackers take over.

With the help of these shadow workers, North Korean hackers have stolen over $3 billion over the past five years, as per Chainalysis.

Becoming increasingly sophisticated

As per the WSJ report, North Korean hackers have demonstrated technical sophistication in hacks that have impressed U.S. officials and researchers. They have pulled off elaborate maneuvers that have never been observed before, the report stated.

For instance, North Korean hackers perpetrated what some researchers called a first-of-its-kind cascading supply-chain attack last year.

They first attacked Trading Technologies, which develops online trading software. An employee of 3CX, a customer of Trading Technologies, downloaded a corrupted version of Trading Technologies software. Then the hackers corrupted 3CX software and used it to hack 3CX customers, including cryptocurrency exchanges.

Share this
Tags

Must-read

The Great Bitcoin Crash of 2024

Bitcoin Crash The cryptocurrency world faced the hell of early 2024 when the most popular Bitcoin crashed by over 80% in a matter of weeks,...

Bitcoin Gambling: A comprehensive guide in 2024

Bitcoin Gambling With online currencies rapidly gaining traditional acceptance, the intriguing convergence of the crypto-trek and gambling industries is taking place. Cryptocurrency gambling, which started...

The Rise of Bitcoin Extractor: A comprehensive guide 2024

Bitcoin Extractor  Crypto mining is resources-thirsty with investors in mining hardware and those investing in the resources needed as the main beneficiaries. In this sense,...

Recent articles

More like this