How North Korean Hackers Steal Millions in Crypto by Pretending to Be Your Next Recruiter

As a seasoned crypto investor with over two decades in the tech industry, I’ve seen my fair share of cyber threats and scams. However, the latest revelations about North Korean hackers impersonating IT professionals and venture capitalists to steal millions in cryptocurrency has left me more than just alarmed.


At this year’s Cyberwarcon, a major cybersecurity gathering, experts unveiled that North Korean hackers have been successfully posing as tech/IT professionals to pilfer millions in cryptocurrency and confidential business data. They have disguised themselves as venture capitalists, recruiters, and remote workers, tricking their targets into revealing sensitive information. This deception has reportedly resulted in the theft of billions of dollars’ worth of digital assets.

James Eliott, a Microsoft security specialist, stated that North Korean operatives have penetrated approximately 300 international organizations by assuming fictitious identities. Researchers have issued alerts about the continuous attempts to impersonate job applicants at multinational firms as a means for the regime to evade sanctions and acquire corporate secrets beneficial to their nuclear program. The shift towards remote work due to the pandemic has made it easier for many corporate spies, since it is not unusual for an employee to be hired without ever setting foot in the workplace.

One team, referred to as Sapphire Sleet, operates undercover as recruiters or venture capitalists, deceiving victims into installing Malware. Posing as solution providers for a malfunctioning meeting room, or as recruiters offering a skills assessment, the impostors coerce victims into downloading this seemingly useful software. The deception enables them to gain access to other data on the computer, including cryptocurrency wallets. Microsoft has reported that North Korea has swindled at least US$10 million in cryptocurrency by employing this tactic.

Read More

2024-12-03 18:24