Publish: 17:16, 29 Nov, 2024 Updated: 17:58, 29 Nov, 2024

North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros

Online Desk
North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros
Symbolic

Security researchers have revealed a new dimension to North Korea’s cyber operations, involving imposters posing as venture capitalists, recruiters, and remote IT workers to steal cryptocurrency and corporate secrets. These efforts, they warn, have generated billions of dollars in stolen funds, helping the regime dodge international sanctions and fund its nuclear weapons program.

At Cyberwarcon, an annual cybersecurity conference in Washington, D.C., experts detailed the methods North Korean hackers use to infiltrate multinational corporations. James Elliott, a Microsoft security researcher, highlighted how North Korean IT workers have infiltrated "hundreds" of organizations globally, using false identities and U.S.-based intermediaries to bypass financial sanctions.

“North Korean IT workers are a triple threat,” Microsoft noted, referring to their ability to deceptively secure jobs, earn money for the regime, steal intellectual property, and extort their employers.

The researchers described a range of tactics employed by various North Korean hacking groups. One group, dubbed "Ruby Sleet" by Microsoft, targeted aerospace and defense companies to steal secrets for advancing weapons and navigation systems. Another group, "Sapphire Sleet," focused on cryptocurrency theft by impersonating recruiters and venture capitalists.

In fake venture capitalist schemes, the hackers lured victims into virtual meetings designed to fail, then pressured them to download malware disguised as troubleshooting tools. In fake recruitment efforts, victims were asked to complete a skills assessment, which also contained malware. This malware enabled hackers to access cryptocurrency wallets and other sensitive data. Microsoft reported that at least $10 million in cryptocurrency was stolen in just six months.

The most persistent threat comes from North Korean hackers taking advantage of the post-pandemic remote work boom. By securing remote jobs under false pretenses, they earn salaries that support the regime and gain access to sensitive company data.

Security firm KnowBe4 admitted earlier this year that it had unknowingly hired a North Korean operative. Once discovered, the company blocked the worker's access and confirmed no data was compromised. However, most victims remain silent, highlighting the challenges in addressing this growing threat.

North Korea’s cyber operations, described as a complex network of hacking groups with varying techniques but unified goals, face little international retaliation due to the country’s heavily sanctioned status. These activities underline the regime’s reliance on cybercrime to finance its ambitions while avoiding traditional economic constraints.

North Korean IT worker schemes have become increasingly sophisticated, with operatives creating online accounts such as LinkedIn profiles and GitHub pages to establish credibility, according to security researchers. Using AI technologies like face-swapping and voice-changing software, these workers craft elaborate false identities to secure remote jobs and further the regime’s agenda.

Once hired, companies unknowingly ship laptops to U.S.-based addresses managed by facilitators. These facilitators set up farms of company-issued devices, installing remote access software that allows North Korean operatives to log in from abroad, effectively masking their true locations. Microsoft noted that many of these operatives work not only from North Korea but also from allied nations like Russia and China, further complicating efforts to detect them.

Microsoft researcher James Elliott revealed the discovery of an inadvertently public repository linked to a North Korean IT worker, providing critical insights into the operation. The repository included dossiers, resumes, and spreadsheets detailing false identities and the profits generated by these campaigns. Elliott described the repository as containing the hackers' "entire playbooks," enabling a clearer understanding of their tactics.

To bolster the credibility of their fake personas, North Korean IT workers immediately verify their LinkedIn accounts as soon as they receive a company email address. However, researchers highlighted instances of sloppiness that exposed their true nature.

Hoi Myong and a researcher known as SttyK shared their methods for identifying suspected North Korean IT workers during a Cyberwarcon talk. In one case, they contacted an IT worker claiming to be Japanese but found linguistic errors in their communications, such as using phrases that don’t exist in the Japanese language. Other red flags included discrepancies in claimed locations and bank account details, such as having a Chinese account but an IP address tracing to Russia.

The U.S. government has imposed sanctions on North Korean-linked organizations involved in these schemes. The FBI has also warned about the use of AI-generated deepfake imagery to secure tech jobs. In 2024, prosecutors charged individuals involved in operating laptop farms used to bypass sanctions.

Despite these efforts, researchers emphasized that companies must improve their employee vetting processes. "They’re not going away," Elliott warned. "They’re gonna be here for a long time."

(Source: TechCrunch)

BD-Pratidin English/Mazdud

More News
TikTok to ban beauty filters for teens
TikTok to ban beauty filters for teens
New Mexico man awarded $412 million medical malpractice payout for botched injections
New Mexico man awarded $412 million medical malpractice payout for botched injections
Alibaba unveils 'Open' competitor to OpenAI’s o1 reasoning model
Alibaba unveils 'Open' competitor to OpenAI’s o1 reasoning model
Solar Orbiter captures the highest-resolution images of the sun’s surface yet
Solar Orbiter captures the highest-resolution images of the sun’s surface yet
How to spot malware on your smartphone: Key Indicators
How to spot malware on your smartphone: Key Indicators
Starlink unveils direct-to-cell satellite service for smartphones
Starlink unveils direct-to-cell satellite service for smartphones
Tesla looks to build teleoperations team for Robotaxi service
Tesla looks to build teleoperations team for Robotaxi service
Indonesia rejects Apple’s $100m investment proposal
Indonesia rejects Apple’s $100m investment proposal
Scientists to build robots to bring dinosaurs back to life
Scientists to build robots to bring dinosaurs back to life
Earth’s ‘mini moon’ may have been a chunk of our actual moon
Earth’s ‘mini moon’ may have been a chunk of our actual moon
AI to create your Instagram profile
AI to create your Instagram profile
FTC investigates Microsoft for anticompetitive practices targeting government contracts
FTC investigates Microsoft for anticompetitive practices targeting government contracts
Latest News
Rizvi accuses Sheikh Hasina of "crocodile tears" over Chinmoy's arrest
Rizvi accuses Sheikh Hasina of "crocodile tears" over Chinmoy's arrest

17 minutes ago | National

Body of missing boy recovered in Bogura
Body of missing boy recovered in Bogura

33 minutes ago | City

Gaza toll rises to 44,363
Gaza toll rises to 44,363

37 minutes ago | International

Minority groups in Bangladesh feel safer under interim government: VoA survey
Minority groups in Bangladesh feel safer under interim government: VoA survey

42 minutes ago | National

UAE pardons 75 more Bangladeshis
UAE pardons 75 more Bangladeshis

1 hour ago | National

Conspiracy all around, need to remain vigilant: Jamaat Ameer
Conspiracy all around, need to remain vigilant: Jamaat Ameer

1 hour ago | National

UGC issues warning against admission to 8 private universities in Bangladesh
UGC issues warning against admission to 8 private universities in Bangladesh

1 hour ago | National

UN’s top court to hold 'Historic Hearings' on climate crisis
UN’s top court to hold 'Historic Hearings' on climate crisis

1 hour ago | International

Fight misformation campaign with truth: CA's Press Secretary
Fight misformation campaign with truth: CA's Press Secretary

1 hour ago | National

UNRWA reports Gaza endures 'Most Intense Bombardment' since World War II
UNRWA reports Gaza endures 'Most Intense Bombardment' since World War II

1 hour ago | International

North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros
North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros

2 hours ago | Tech

No one will be spared for lawyer's murder: Religious Adviser
No one will be spared for lawyer's murder: Religious Adviser

2 hours ago | National

1C fund announced for slain Chattogram lawyer’s family
1C fund announced for slain Chattogram lawyer’s family

2 hours ago | National

Massive $80 billion gold mine discovered in China
Massive $80 billion gold mine discovered in China

2 hours ago | Economy

Messi's nomination for best FIFA men's player 2024 stuns football world
Messi's nomination for best FIFA men's player 2024 stuns football world

2 hours ago | Sports

Which countries recognise Palestine in 2024?
Which countries recognise Palestine in 2024?

2 hours ago | International

Virat Kohli ousted as India's highest-earning cricketer but by whom?
Virat Kohli ousted as India's highest-earning cricketer but by whom?

2 hours ago | Sports

Ireland votes in tight parliamentary election
Ireland votes in tight parliamentary election

3 hours ago | International

Jayasuriya becomes fastest to hold 100 Test Wickets
Jayasuriya becomes fastest to hold 100 Test Wickets

3 hours ago | Sports

India’s duplicity is condemnable, objectionable: Law adviser
India’s duplicity is condemnable, objectionable: Law adviser

3 hours ago | National

Tk 1.9 million fined, 40,000 kg polythene seized in anti-polythene campaign
Tk 1.9 million fined, 40,000 kg polythene seized in anti-polythene campaign

3 hours ago | National

Salehuddin calls for inclusive public financial management reform
Salehuddin calls for inclusive public financial management reform

3 hours ago | Economy

Its not possible to defeat fascism without united efforts: Nazrul Islam Khan
Its not possible to defeat fascism without united efforts: Nazrul Islam Khan

3 hours ago | National

Hybrid model for Champions Trophy not acceptable: PCB
Hybrid model for Champions Trophy not acceptable: PCB

3 hours ago | Sports

Why Billboard apologizes to Taylor Swift?
Why Billboard apologizes to Taylor Swift?

3 hours ago | Entertainment

Dhaka’s air quality ‘unhealthy’ this morning
Dhaka’s air quality ‘unhealthy’ this morning

4 hours ago | City

Long-distance bus services restart from Benapole after six-day suspension
Long-distance bus services restart from Benapole after six-day suspension

4 hours ago | National

Electoral offenders in last 3 polls should be punished: Dr Badiul Alam
Electoral offenders in last 3 polls should be punished: Dr Badiul Alam

4 hours ago | National

Primary students take part in Bangla alphabet contest
Primary students take part in Bangla alphabet contest

4 hours ago | Shuvosangho

Ex-nursery school worker jailed for 'depraved' crimes against children
Ex-nursery school worker jailed for 'depraved' crimes against children

4 hours ago | International

Most Read
Vested groups trying to destroy communal harmony: Nur
Vested groups trying to destroy communal harmony: Nur

20 hours ago | National

Sean 'Diddy' Combs denied bail ahead of sex-trafficking trial
Sean 'Diddy' Combs denied bail ahead of sex-trafficking trial

7 hours ago | Entertainment

Entrepreneurs concerned as NPLs likely to increase
Entrepreneurs concerned as NPLs likely to increase

10 hours ago | Special

Who will account for 17 lakh crores of smuggled funds?
Who will account for 17 lakh crores of smuggled funds?

7 hours ago | Economy

Business collapses in Kolkata New Market
Business collapses in Kolkata New Market

7 hours ago | National

Israel claims to kill some 3,500 Hezbollah operatives
Israel claims to kill some 3,500 Hezbollah operatives

9 hours ago | International

Nordic countries prepare citizens for possible war
Nordic countries prepare citizens for possible war

6 hours ago | International

Education Adviser urges VCs to encourage students to respect law
Education Adviser urges VCs to encourage students to respect law

9 hours ago | National

ACC computer launched in Bangladesh
ACC computer launched in Bangladesh

6 hours ago | Corporate Corner

Resolve conflicts through dialogue with govt, avoid destructive activities: Adviser Rizwana
Resolve conflicts through dialogue with govt, avoid destructive activities: Adviser Rizwana

21 hours ago | National

Govt faces tough challenge to restore order in every sector
Govt faces tough challenge to restore order in every sector

7 hours ago | Special

Irish women look to bounce back after heartwarming 'Dhaka Welcome'
Irish women look to bounce back after heartwarming 'Dhaka Welcome'

6 hours ago | Sports

Bangladesh bank extends Tk 22,500cr support to several liquidity-crisis hit banks
Bangladesh bank extends Tk 22,500cr support to several liquidity-crisis hit banks

23 hours ago | Economy

Putin threatens Kyiv with new hypersonic missile
Putin threatens Kyiv with new hypersonic missile

9 hours ago | International

Jamaat stresses on national unity in meeting with Chief Adviser
Jamaat stresses on national unity in meeting with Chief Adviser

22 hours ago | National

Israel kills 42 in Gaza amid accusations of truce violations in Lebanon
Israel kills 42 in Gaza amid accusations of truce violations in Lebanon

7 hours ago | International

15 dead, 113 missing in Uganda landslide
15 dead, 113 missing in Uganda landslide

5 hours ago | International

BNP to create a new, inclusive Bangladesh: Tarique
BNP to create a new, inclusive Bangladesh: Tarique

23 hours ago | National

16-day campaign aiming to end violence against women begins
16-day campaign aiming to end violence against women begins

9 hours ago | Shuvosangho

Russian aerial strike leaves 1 million Ukrainian homes without power
Russian aerial strike leaves 1 million Ukrainian homes without power

22 hours ago | International

Israeli airstrikes on Lebanon continue despite ceasefire
Israeli airstrikes on Lebanon continue despite ceasefire

9 hours ago | International

Ex-nursery school worker jailed for 'depraved' crimes against children
Ex-nursery school worker jailed for 'depraved' crimes against children

4 hours ago | International

Hackers steal $17m from Uganda central bank
Hackers steal $17m from Uganda central bank

9 hours ago | International

CMP detains Obaidul Quader's relative
CMP detains Obaidul Quader's relative

8 hours ago | National

'Black Friday' deals target inflation-weary consumers in US
'Black Friday' deals target inflation-weary consumers in US

5 hours ago | Economy

WHO wants bird flu surveillance stepped up
WHO wants bird flu surveillance stepped up

9 hours ago | International

Myanmar explosions shake homes across Bangladesh border
Myanmar explosions shake homes across Bangladesh border

7 hours ago | National

Bus helper dies in Khulna
Bus helper dies in Khulna

7 hours ago | City

Mondera’s ‘Kajol Rekha’ set to participate in Rotterdam Film Festival
Mondera’s ‘Kajol Rekha’ set to participate in Rotterdam Film Festival

4 hours ago | Entertainment

Hridoy sustains groin injury ahead of Windies ODIs
Hridoy sustains groin injury ahead of Windies ODIs

22 hours ago | Sports