Hackers with ties to the North Korean government have reportedly expanded social engineering scams designed to steal cryptocurrencies by infiltrating “hundreds” of large, multinational information technology firms.
According to an article from TechCrunch, researchers at the Cyberwarcon cybersecurity conference identified two North Korean hacker groups called “Sapphire Sleet” and “Ruby Sleet.”
Sapphire Sleet targeted individuals through fraudulent employment schemes by posing as legitimate recruiters and luring unsuspecting victims into interviews or other offers of employment. The hackers would then infect the users’ computers with malware disguised as picture-document files (PDFs) or malicious links at some point during the interview process.
Ruby Sleet managed to infiltrate aerospace and defense contractors in the United States, the United Kingdom, and South Korea to steal military secrets.
Additionally, the report mentioned that North Korean IT workers were using fake identities crafted through AI, social media, and voice-changing technologies to infiltrate the companies and carry out recruitment scams.
Crypto theft for November 2024. Source: Immunefi, Because Bitcoin
North Korean hackers target crypto industry
Long before the researchers at Cyberwarcon issued a warning about North Korean hacking groups targeting information technology companies, hackers associated with the DPRK regime were targeting cryptocurrency firms using the same tactics.
In August, onchain sleuth ZackXBT claimed to have identified 21 developers, believed to be North Koreans, working on various crypto projects using fake identities.
Later, in September, the Federal Bureau of Investigation (FBI) issued a warning about North Korean hackers targeting crypto companies and decentralized finance projects with malware disguised as employment offers. Once the user downloaded the malware or clicked a malicious link, their private keys would be stolen.
More recently, in October, the Cosmos ecosystem faced concerns over its Liquid Staking Module, which was allegedly built by North Korean developers.
At the time, Cosmos ecosystem developer Jacob Gadikian said, “The people who built the LSM are the world’s most skilled and prolific crypto thieves.” The threat of backdoors and other malicious lines of code prompted several security audits of the Cosmos Liquid Staking Module.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis