Publish: 17:16, 29 Nov, 2024 Updated: 17:58, 29 Nov, 2024

North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros

Online Desk
North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros
Symbolic

Security researchers have revealed a new dimension to North Korea’s cyber operations, involving imposters posing as venture capitalists, recruiters, and remote IT workers to steal cryptocurrency and corporate secrets. These efforts, they warn, have generated billions of dollars in stolen funds, helping the regime dodge international sanctions and fund its nuclear weapons program.

At Cyberwarcon, an annual cybersecurity conference in Washington, D.C., experts detailed the methods North Korean hackers use to infiltrate multinational corporations. James Elliott, a Microsoft security researcher, highlighted how North Korean IT workers have infiltrated "hundreds" of organizations globally, using false identities and U.S.-based intermediaries to bypass financial sanctions.

“North Korean IT workers are a triple threat,” Microsoft noted, referring to their ability to deceptively secure jobs, earn money for the regime, steal intellectual property, and extort their employers.

The researchers described a range of tactics employed by various North Korean hacking groups. One group, dubbed "Ruby Sleet" by Microsoft, targeted aerospace and defense companies to steal secrets for advancing weapons and navigation systems. Another group, "Sapphire Sleet," focused on cryptocurrency theft by impersonating recruiters and venture capitalists.

In fake venture capitalist schemes, the hackers lured victims into virtual meetings designed to fail, then pressured them to download malware disguised as troubleshooting tools. In fake recruitment efforts, victims were asked to complete a skills assessment, which also contained malware. This malware enabled hackers to access cryptocurrency wallets and other sensitive data. Microsoft reported that at least $10 million in cryptocurrency was stolen in just six months.

The most persistent threat comes from North Korean hackers taking advantage of the post-pandemic remote work boom. By securing remote jobs under false pretenses, they earn salaries that support the regime and gain access to sensitive company data.

Security firm KnowBe4 admitted earlier this year that it had unknowingly hired a North Korean operative. Once discovered, the company blocked the worker's access and confirmed no data was compromised. However, most victims remain silent, highlighting the challenges in addressing this growing threat.

North Korea’s cyber operations, described as a complex network of hacking groups with varying techniques but unified goals, face little international retaliation due to the country’s heavily sanctioned status. These activities underline the regime’s reliance on cybercrime to finance its ambitions while avoiding traditional economic constraints.

North Korean IT worker schemes have become increasingly sophisticated, with operatives creating online accounts such as LinkedIn profiles and GitHub pages to establish credibility, according to security researchers. Using AI technologies like face-swapping and voice-changing software, these workers craft elaborate false identities to secure remote jobs and further the regime’s agenda.

Once hired, companies unknowingly ship laptops to U.S.-based addresses managed by facilitators. These facilitators set up farms of company-issued devices, installing remote access software that allows North Korean operatives to log in from abroad, effectively masking their true locations. Microsoft noted that many of these operatives work not only from North Korea but also from allied nations like Russia and China, further complicating efforts to detect them.

Microsoft researcher James Elliott revealed the discovery of an inadvertently public repository linked to a North Korean IT worker, providing critical insights into the operation. The repository included dossiers, resumes, and spreadsheets detailing false identities and the profits generated by these campaigns. Elliott described the repository as containing the hackers' "entire playbooks," enabling a clearer understanding of their tactics.

To bolster the credibility of their fake personas, North Korean IT workers immediately verify their LinkedIn accounts as soon as they receive a company email address. However, researchers highlighted instances of sloppiness that exposed their true nature.

Hoi Myong and a researcher known as SttyK shared their methods for identifying suspected North Korean IT workers during a Cyberwarcon talk. In one case, they contacted an IT worker claiming to be Japanese but found linguistic errors in their communications, such as using phrases that don’t exist in the Japanese language. Other red flags included discrepancies in claimed locations and bank account details, such as having a Chinese account but an IP address tracing to Russia.

The U.S. government has imposed sanctions on North Korean-linked organizations involved in these schemes. The FBI has also warned about the use of AI-generated deepfake imagery to secure tech jobs. In 2024, prosecutors charged individuals involved in operating laptop farms used to bypass sanctions.

Despite these efforts, researchers emphasized that companies must improve their employee vetting processes. "They’re not going away," Elliott warned. "They’re gonna be here for a long time."

(Source: TechCrunch)

BD-Pratidin English/Mazdud

More News
OpenAI, Retro Biosciences working to extend ‘human lifespan’
OpenAI, Retro Biosciences working to extend ‘human lifespan’
Pakistan launches first home-made observation satellite
Pakistan launches first home-made observation satellite
Instagram profile grids to switch from squares to rectangles
Instagram profile grids to switch from squares to rectangles
TikTok says it will go dark Sunday without Biden’s interference
TikTok says it will go dark Sunday without Biden’s interference
ISRO releases video of SpaDeX satellite docking
ISRO releases video of SpaDeX satellite docking
Biden won’t enforce TikTok ban, leaving fate of app to Trump
Biden won’t enforce TikTok ban, leaving fate of app to Trump
Why Nintendo Switch 2 creating new wave of hype
Why Nintendo Switch 2 creating new wave of hype
SpaceX Starship test ends in failure after successful booster catch at launch pad
SpaceX Starship test ends in failure after successful booster catch at launch pad
Elon Musk reacts to Tulip Siddiq’s resignation
Elon Musk reacts to Tulip Siddiq’s resignation
Bezos' New Glenn reaches orbit in first launch
Bezos' New Glenn reaches orbit in first launch
ChatGPT introduces reminder and to-do management feature
ChatGPT introduces reminder and to-do management feature
Zuckerberg cites YouTube in defense of Meta's AI copyright case
Zuckerberg cites YouTube in defense of Meta's AI copyright case
Latest News
BPL, a platform to unleash young cricketers: Aurther
BPL, a platform to unleash young cricketers: Aurther
42 minutes ago | Sports
Jamal wants more footballers like Hamza to play for Bangladesh
Jamal wants more footballers like Hamza to play for Bangladesh
50 minutes ago | Sports
Israeli airport suspends flights following Yemen's attack
Israeli airport suspends flights following Yemen's attack
52 minutes ago | International
Commerce adviser defends govt’s move to increase VAT
Commerce adviser defends govt’s move to increase VAT
59 minutes ago | National
Recommendation made to cut addl duty on drugs: Adviser
Recommendation made to cut addl duty on drugs: Adviser
1 hour ago | National
Tigress start U19 T20 World Cup defeating Nepal
Tigress start U19 T20 World Cup defeating Nepal
1 hour ago | Sports
Civic volunteer convicted in RG Kar rape-murder case
Civic volunteer convicted in RG Kar rape-murder case
1 hour ago | International
Don’t elect thieves: M Shakhawat
Don’t elect thieves: M Shakhawat
1 hour ago | National
Review hearing to restore caretaker government tomorrow
Review hearing to restore caretaker government tomorrow
1 hour ago | National
Foreigners in Bangladesh increase spending on credit cards
Foreigners in Bangladesh increase spending on credit cards
2 hours ago | Business
37 lakh TCB family cardholders are fakes: Commerce adviser
37 lakh TCB family cardholders are fakes: Commerce adviser
2 hours ago | National
DMP files 3,251 traffic violation cases in Dhaka
DMP files 3,251 traffic violation cases in Dhaka
2 hours ago | City
Two judges murdered outside Iran's Supreme Court: media
Two judges murdered outside Iran's Supreme Court: media
3 hours ago | International
‘Palestinians, resistance thwarted Israel’s big plots in Gaza’
‘Palestinians, resistance thwarted Israel’s big plots in Gaza’
3 hours ago | International
EU ready to support Bangladesh during its political transition: Envoy
EU ready to support Bangladesh during its political transition: Envoy
3 hours ago | National
British sci-fi classic ‘Doctor Who’ gears up for bold new adventures
British sci-fi classic ‘Doctor Who’ gears up for bold new adventures
3 hours ago | Entertainment
Bangladesh bowl out Nepal for 52 runs
Bangladesh bowl out Nepal for 52 runs
3 hours ago | Sports
Night temperature may drop in parts of country
Night temperature may drop in parts of country
3 hours ago | National
Ready to govern Gaza: Palestine’s President
Ready to govern Gaza: Palestine’s President
4 hours ago | International
"Current govt at risk by continuing budget of ousted Awami League"
"Current govt at risk by continuing budget of ousted Awami League"
4 hours ago | National
OpenAI, Retro Biosciences working to extend ‘human lifespan’
OpenAI, Retro Biosciences working to extend ‘human lifespan’
4 hours ago | Tech
Srijit Mukherji from aspiring sports journalist to filmmaker
Srijit Mukherji from aspiring sports journalist to filmmaker
4 hours ago | Entertainment
Pakistan launches first home-made observation satellite
Pakistan launches first home-made observation satellite
4 hours ago | Tech
Govt reaffirms zero tolerance on shrine attacks, urges complaints
Govt reaffirms zero tolerance on shrine attacks, urges complaints
5 hours ago | National
BNP demands withdrawal of vat on over 100 products
BNP demands withdrawal of vat on over 100 products
5 hours ago | National
Met office assumes dry weather nationwide
Met office assumes dry weather nationwide
5 hours ago | National
Marma girl's accident injury being propagated as communal murder
Marma girl's accident injury being propagated as communal murder
5 hours ago | National
Tarique seeks prayers for mother
Tarique seeks prayers for mother
5 hours ago | National
Cold wave set to arrive, says Meteorological Department
Cold wave set to arrive, says Meteorological Department
5 hours ago | National
How to make smacked cucumbers
How to make smacked cucumbers
6 hours ago | Lifestyle
Most Read
Won't stop until misrule-free Bangladesh is established
Won't stop until misrule-free Bangladesh is established
22 hours ago | National
Youth can change country's image: Fakhrul
Youth can change country's image: Fakhrul
21 hours ago | National
OpenAI, Retro Biosciences working to extend ‘human lifespan’
OpenAI, Retro Biosciences working to extend ‘human lifespan’
4 hours ago | Tech
Country at 5 risks, inflation at top
Country at 5 risks, inflation at top
9 hours ago | National
Night temperature may drop in parts of country
Night temperature may drop in parts of country
3 hours ago | National
Import duty hike sends fruit market in turmoil
Import duty hike sends fruit market in turmoil
9 hours ago | Business
Over 50,000 garment workers unemployed in a year
Over 50,000 garment workers unemployed in a year
7 hours ago | Special
Bangladesh’s 2025-26 budget may reach 8 trillion
Bangladesh’s 2025-26 budget may reach 8 trillion
6 hours ago | National
How to make smacked cucumbers
How to make smacked cucumbers
6 hours ago | Lifestyle
Unsweetened coffee reduces Alzheimer's disease risk by 30%
Unsweetened coffee reduces Alzheimer's disease risk by 30%
9 hours ago | Lifestyle
Hamas set to release first hostages under Gaza ceasefire deal: Israel
Hamas set to release first hostages under Gaza ceasefire deal: Israel
23 hours ago | International
Cold wave set to arrive, says Meteorological Department
Cold wave set to arrive, says Meteorological Department
5 hours ago | National
Tarique seeks prayers for mother
Tarique seeks prayers for mother
5 hours ago | National
UK to announce significant hike in visa sponsorship fees
UK to announce significant hike in visa sponsorship fees
9 hours ago | International
Srijit Mukherji from aspiring sports journalist to filmmaker
Srijit Mukherji from aspiring sports journalist to filmmaker
4 hours ago | Entertainment
Instagram profile grids to switch from squares to rectangles
Instagram profile grids to switch from squares to rectangles
7 hours ago | Tech
Debapriya slams 'inconsiderate' VAT hike by interim govt
Debapriya slams 'inconsiderate' VAT hike by interim govt
6 hours ago | National
BNP focuses entirely on elections
BNP focuses entirely on elections
7 hours ago | Special
Bangladesh bowl out Nepal for 52 runs
Bangladesh bowl out Nepal for 52 runs
3 hours ago | Sports
Inaugural Women's BPL to kick off in February with 3 teams
Inaugural Women's BPL to kick off in February with 3 teams
22 hours ago | Sports
Israeli security cabinet approves Gaza ceasefire deal
Israeli security cabinet approves Gaza ceasefire deal
22 hours ago | International
Dhaka's air quality 2nd worst globally this morning
Dhaka's air quality 2nd worst globally this morning
9 hours ago | City
It's never going to get easy: Abhishek amid separation rumors
It's never going to get easy: Abhishek amid separation rumors
6 hours ago | Entertainment
1,246 Bangladeshis repatriated from Lebanon; 47 arrive today
1,246 Bangladeshis repatriated from Lebanon; 47 arrive today
7 hours ago | National
Aafia Siddiqui appeals for presidential pardon before Trump's takeover
Aafia Siddiqui appeals for presidential pardon before Trump's takeover
6 hours ago | International
"Current govt at risk by continuing budget of ousted Awami League"
"Current govt at risk by continuing budget of ousted Awami League"
4 hours ago | National
Rangpur Riders extend perfect winning streak to eight
Rangpur Riders extend perfect winning streak to eight
10 hours ago | Sports
116 Palestinians killed since agreement announced
116 Palestinians killed since agreement announced
8 hours ago | International
8 health benefits of garlic
8 health benefits of garlic
7 hours ago | Lifestyle
‘Groups to be formed in districts-upazilas-unions to combat injustice’
‘Groups to be formed in districts-upazilas-unions to combat injustice’
23 hours ago | National