- Six DPRK operatives ran 31 fake identities to land global blockchain and crypto jobs.
- Hackers used LinkedIn, Upwork, VPNs, AnyDesk, and Google tools for coordination and disguise.
A counter-hack has revealed a complex North Korean IT worker network, really using thirty-one personas to breach crypto companies. The six-person team, which was linked to a $680K hack, utilised commercially available tools like Google Drive, remote access software and computers to do so.
A reverse-hacking operation has revealed the inner dynamics of the network of IT workers in North Korea who stole hundreds of millions of dollars out of crypto companies. According to crypto investigator ZachXBT, it was discovered that six operatives operated thirty-one fake identities. This was to obtain genuine blockchain development jobs in various firms globally.
Such digital impersonators developed entire false identities, buying government identification papers, phone numbers, and professional networking accounts. They used sites such as LinkedIn and Upwork. They were well organised and would script answers to interview questions. That would make them sound like they had worked at major companies such as OpenSea and Chainlink.
Inside the DPRK Digital Deception Campaign
The operatives were able to secure the jobs of blockchain developers and smart contract engineers with the help of freelance websites. They used remote access programs such as AnyDesk to work. They likely hid their actual locations with the help of virtual private networks and proxy services.
Internal documents confirmed that mainstream tech tools provided all operational coordination. Tracking expense reports relied on Google Drive spreadsheets, which showed the total expenses added up to almost $1500 in May. The Chrome browser profiles tracked multiple fake identities concurrently. Workers were mostly communicating in English while taking advantage of Google translation services for Korean-to-English translations.
The financial data illustrated how the group went from converting fiat currency to cryptocurrency via Payoneer payment systems. Each crypto wallet replayed the characteristics of their financial transactions, while part of their activity included one wallet address that was connected to the $680,000 Favrr marketplace exploitation. This suggests the group shifted from initial infiltration of an organisation to direct theft operations.
The leaked information revealed what the group was looking for in areas of interest. How to deploy Ethereum tokens on Solana networks and locate European AI development companies. It indicates that their methods were expanding their operational reach to emerging tech beyond the more traditional cryptocurrency targets.
Security experts pointed out that these infiltration attempts usually succeed because of an inadequate hiring verification mechanism. Notably, not because of advanced technical manipulation. The number of remote work applications often overwhelms screening procedures. This is making it much easier for bad actors to infiltrate and gain access to sensitive information.
Prior North Korean activity has shown increasing ambition, most notably the sizable Bitbit exchange theft for over one billion dollars. These events show the pressing need for due diligence procedures within the cryptocurrency and technology sectors to prevent infiltrations of this type.
Highlighted Crypto News Today:
Solana (SOL) Bulls Back in Action, Is It Real Momentum or a Mirage?
