Publish: 17:16, 29 Nov, 2024 Updated: 17:58, 29 Nov, 2024

North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros

Online Desk
North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros
Symbolic

Security researchers have revealed a new dimension to North Korea’s cyber operations, involving imposters posing as venture capitalists, recruiters, and remote IT workers to steal cryptocurrency and corporate secrets. These efforts, they warn, have generated billions of dollars in stolen funds, helping the regime dodge international sanctions and fund its nuclear weapons program.

At Cyberwarcon, an annual cybersecurity conference in Washington, D.C., experts detailed the methods North Korean hackers use to infiltrate multinational corporations. James Elliott, a Microsoft security researcher, highlighted how North Korean IT workers have infiltrated "hundreds" of organizations globally, using false identities and U.S.-based intermediaries to bypass financial sanctions.

“North Korean IT workers are a triple threat,” Microsoft noted, referring to their ability to deceptively secure jobs, earn money for the regime, steal intellectual property, and extort their employers.

The researchers described a range of tactics employed by various North Korean hacking groups. One group, dubbed "Ruby Sleet" by Microsoft, targeted aerospace and defense companies to steal secrets for advancing weapons and navigation systems. Another group, "Sapphire Sleet," focused on cryptocurrency theft by impersonating recruiters and venture capitalists.

In fake venture capitalist schemes, the hackers lured victims into virtual meetings designed to fail, then pressured them to download malware disguised as troubleshooting tools. In fake recruitment efforts, victims were asked to complete a skills assessment, which also contained malware. This malware enabled hackers to access cryptocurrency wallets and other sensitive data. Microsoft reported that at least $10 million in cryptocurrency was stolen in just six months.

The most persistent threat comes from North Korean hackers taking advantage of the post-pandemic remote work boom. By securing remote jobs under false pretenses, they earn salaries that support the regime and gain access to sensitive company data.

Security firm KnowBe4 admitted earlier this year that it had unknowingly hired a North Korean operative. Once discovered, the company blocked the worker's access and confirmed no data was compromised. However, most victims remain silent, highlighting the challenges in addressing this growing threat.

North Korea’s cyber operations, described as a complex network of hacking groups with varying techniques but unified goals, face little international retaliation due to the country’s heavily sanctioned status. These activities underline the regime’s reliance on cybercrime to finance its ambitions while avoiding traditional economic constraints.

North Korean IT worker schemes have become increasingly sophisticated, with operatives creating online accounts such as LinkedIn profiles and GitHub pages to establish credibility, according to security researchers. Using AI technologies like face-swapping and voice-changing software, these workers craft elaborate false identities to secure remote jobs and further the regime’s agenda.

Once hired, companies unknowingly ship laptops to U.S.-based addresses managed by facilitators. These facilitators set up farms of company-issued devices, installing remote access software that allows North Korean operatives to log in from abroad, effectively masking their true locations. Microsoft noted that many of these operatives work not only from North Korea but also from allied nations like Russia and China, further complicating efforts to detect them.

Microsoft researcher James Elliott revealed the discovery of an inadvertently public repository linked to a North Korean IT worker, providing critical insights into the operation. The repository included dossiers, resumes, and spreadsheets detailing false identities and the profits generated by these campaigns. Elliott described the repository as containing the hackers' "entire playbooks," enabling a clearer understanding of their tactics.

To bolster the credibility of their fake personas, North Korean IT workers immediately verify their LinkedIn accounts as soon as they receive a company email address. However, researchers highlighted instances of sloppiness that exposed their true nature.

Hoi Myong and a researcher known as SttyK shared their methods for identifying suspected North Korean IT workers during a Cyberwarcon talk. In one case, they contacted an IT worker claiming to be Japanese but found linguistic errors in their communications, such as using phrases that don’t exist in the Japanese language. Other red flags included discrepancies in claimed locations and bank account details, such as having a Chinese account but an IP address tracing to Russia.

The U.S. government has imposed sanctions on North Korean-linked organizations involved in these schemes. The FBI has also warned about the use of AI-generated deepfake imagery to secure tech jobs. In 2024, prosecutors charged individuals involved in operating laptop farms used to bypass sanctions.

Despite these efforts, researchers emphasized that companies must improve their employee vetting processes. "They’re not going away," Elliott warned. "They’re gonna be here for a long time."

(Source: TechCrunch)

BD-Pratidin English/Mazdud

More News
Egypt unveils first pharaoh’s tomb in century
Egypt unveils first pharaoh’s tomb in century
Apple launches sleeker, pricier iPhone of its lowest priced iPhone
Apple launches sleeker, pricier iPhone of its lowest priced iPhone
SpaceX makes history with Falcon 9 launch and booster landing in the Bahamas
SpaceX makes history with Falcon 9 launch and booster landing in the Bahamas
Tesla may launch EV sales in India by April, prices likely to start at $25,000
Tesla may launch EV sales in India by April, prices likely to start at $25,000
Facebook to delete live broadcast recordings after 30 days
Facebook to delete live broadcast recordings after 30 days
NASA says probability of "city-killer" asteroid impact in 2032 to 3.1%
NASA says probability of "city-killer" asteroid impact in 2032 to 3.1%
Why countries are banning DeepSeek?
Why countries are banning DeepSeek?
Malaysia calls for stronger cooperation to combat illegal e-waste processing
Malaysia calls for stronger cooperation to combat illegal e-waste processing
Top AI models: Features and how to use them
Top AI models: Features and how to use them
Musk’s xAI launches Grok 3 AI model
Musk’s xAI launches Grok 3 AI model
AI models lose cognitive abilities with age, just like humans: Study
AI models lose cognitive abilities with age, just like humans: Study
Meta plans globe-spanning sub-sea internet cable
Meta plans globe-spanning sub-sea internet cable
Latest News
Israel to release 602 prisoners in Gaza swap Saturday: Palestinian NGO
Israel to release 602 prisoners in Gaza swap Saturday: Palestinian NGO
3 hours ago | International
Fire breaks out at sawmill in Khilgaon
Fire breaks out at sawmill in Khilgaon
4 hours ago | City
Babar returns home performing Umrah
Babar returns home performing Umrah
4 hours ago | National
Champions Trophy: Rickelton, Markram power proteas to 315 against Afghans
Champions Trophy: Rickelton, Markram power proteas to 315 against Afghans
5 hours ago | Sports
It’s not that you will forget Bengali just by learning English: CA
It’s not that you will forget Bengali just by learning English: CA
5 hours ago | National
Independence won thru student-mass people's blood must be retained: Annie
Independence won thru student-mass people's blood must be retained: Annie
6 hours ago | National
Bangladesh embassy in Tokyo observes IML Day
Bangladesh embassy in Tokyo observes IML Day
7 hours ago | National
Faruque warns of conspiracy if election is delayed
Faruque warns of conspiracy if election is delayed
7 hours ago | National
Govt emphasizes preserving endangered languages ​​and ensuring diversity: Foreign Secretary
Govt emphasizes preserving endangered languages ​​and ensuring diversity: Foreign Secretary
8 hours ago | National
Saudi Ambassador extends greetings in Bengali on Feb 21
Saudi Ambassador extends greetings in Bengali on Feb 21
8 hours ago | National
Discussion on mother tongue held in Bandarban
Discussion on mother tongue held in Bandarban
8 hours ago | Shuvosangho
No pain, no gain? Hardly. This year’s fitness buzzword is ‘recovery’
No pain, no gain? Hardly. This year’s fitness buzzword is ‘recovery’
8 hours ago | Lifestyle
Poland introduces mandatory firearms training for children
Poland introduces mandatory firearms training for children
8 hours ago | International
Only election can restore true democracy: Rizvi
Only election can restore true democracy: Rizvi
9 hours ago | National
25 foreign nationals pay tribute to language martyrs
25 foreign nationals pay tribute to language martyrs
9 hours ago | National
South Africa wins the toss, decides to bat against Afghanistan
South Africa wins the toss, decides to bat against Afghanistan
10 hours ago | Sports
Hamas gave body of 'Gazan woman' not hostage Shiri Bibas: Netanyahu
Hamas gave body of 'Gazan woman' not hostage Shiri Bibas: Netanyahu
10 hours ago | International
ADB, World Bank partner on FMRF to increase development impact
ADB, World Bank partner on FMRF to increase development impact
10 hours ago | Business
Imported fruit prices surge by up to Tk100 per Kg ahead of Ramadan
Imported fruit prices surge by up to Tk100 per Kg ahead of Ramadan
11 hours ago | Business
Climate change is shrinking glaciers faster than ever
Climate change is shrinking glaciers faster than ever
11 hours ago | International
CIA plans largest mass firing in nearly 50 years: New York Times
CIA plans largest mass firing in nearly 50 years: New York Times
11 hours ago | International
Gill’s ton guides India to a comfortable win over Bangladesh
Gill’s ton guides India to a comfortable win over Bangladesh
11 hours ago | Sports
Alibaba sees revenue surge on back of artificial intelligence, e-commerce
Alibaba sees revenue surge on back of artificial intelligence, e-commerce
11 hours ago | Business
Netanyahu orders 'intensive' West Bank operations after Israel bus blasts
Netanyahu orders 'intensive' West Bank operations after Israel bus blasts
12 hours ago | International
BGB DG pays tribute to language martyrs
BGB DG pays tribute to language martyrs
13 hours ago | National
IGP pays tribute to language heroes
IGP pays tribute to language heroes
13 hours ago | National
Investigation underway into 2 former BB governors, 53 officials
Investigation underway into 2 former BB governors, 53 officials
13 hours ago | Special
SMEs struggle due to high interest rates, tough loans
SMEs struggle due to high interest rates, tough loans
13 hours ago | Business
Trump seeks to reshape Asia's energy supplies with US gas
Trump seeks to reshape Asia's energy supplies with US gas
14 hours ago | International
Chief adviser pays tribute to language martyrs
Chief adviser pays tribute to language martyrs
14 hours ago | National
Most Read
SMEs struggle due to high interest rates, tough loans
SMEs struggle due to high interest rates, tough loans
14 hours ago | Business
IGP pays tribute to language heroes
IGP pays tribute to language heroes
13 hours ago | National
Investigation underway into 2 former BB governors, 53 officials
Investigation underway into 2 former BB governors, 53 officials
13 hours ago | Special
Not enough steps to prevent loss of ethnic languages
Not enough steps to prevent loss of ethnic languages
17 hours ago | National
Imported fruit prices surge by up to Tk100 per Kg ahead of Ramadan
Imported fruit prices surge by up to Tk100 per Kg ahead of Ramadan
11 hours ago | Business
25 foreign nationals pay tribute to language martyrs
25 foreign nationals pay tribute to language martyrs
10 hours ago | National
Chief adviser pays tribute to language martyrs
Chief adviser pays tribute to language martyrs
15 hours ago | National
Alibaba sees revenue surge on back of artificial intelligence, e-commerce
Alibaba sees revenue surge on back of artificial intelligence, e-commerce
11 hours ago | Business
Trump seeks to reshape Asia's energy supplies with US gas
Trump seeks to reshape Asia's energy supplies with US gas
14 hours ago | International
Dhaka faces another day of 'very unhealthy' air
Dhaka faces another day of 'very unhealthy' air
16 hours ago | City
Partly cloudy skies expected over Dhaka
Partly cloudy skies expected over Dhaka
16 hours ago | City
People can spread bird flu to their cats, US study suggests
People can spread bird flu to their cats, US study suggests
15 hours ago | Lifestyle
BGB DG pays tribute to language martyrs
BGB DG pays tribute to language martyrs
13 hours ago | National
Body returned from Gaza is not Shiri Bibas, Israeli military says
Body returned from Gaza is not Shiri Bibas, Israeli military says
16 hours ago | International
US imposes sanctions on drivers of violence in Congo
US imposes sanctions on drivers of violence in Congo
16 hours ago | International
Govt initiates action against ex-DCs
Govt initiates action against ex-DCs
16 hours ago | National
Gill’s ton guides India to a comfortable win over Bangladesh
Gill’s ton guides India to a comfortable win over Bangladesh
11 hours ago | Sports
CIA plans largest mass firing in nearly 50 years: New York Times
CIA plans largest mass firing in nearly 50 years: New York Times
11 hours ago | International
Faruque warns of conspiracy if election is delayed
Faruque warns of conspiracy if election is delayed
7 hours ago | National
DMP assures full cooperation in providing security for BAJUS members
DMP assures full cooperation in providing security for BAJUS members
17 hours ago | Business
US designates major cartels, transnational organizations as terrorist groups
US designates major cartels, transnational organizations as terrorist groups
16 hours ago | International
Only election can restore true democracy: Rizvi
Only election can restore true democracy: Rizvi
9 hours ago | National
Netanyahu orders 'intensive' West Bank operations after Israel bus blasts
Netanyahu orders 'intensive' West Bank operations after Israel bus blasts
12 hours ago | International
No pain, no gain? Hardly. This year’s fitness buzzword is ‘recovery’
No pain, no gain? Hardly. This year’s fitness buzzword is ‘recovery’
9 hours ago | Lifestyle
Govt emphasizes preserving endangered languages ​​and ensuring diversity: Foreign Secretary
Govt emphasizes preserving endangered languages ​​and ensuring diversity: Foreign Secretary
8 hours ago | National
It’s not that you will forget Bengali just by learning English: CA
It’s not that you will forget Bengali just by learning English: CA
5 hours ago | National
Turkiye FM Fidan, Chinese counterpart discuss global security concerns
Turkiye FM Fidan, Chinese counterpart discuss global security concerns
15 hours ago | International
Hamas gave body of 'Gazan woman' not hostage Shiri Bibas: Netanyahu
Hamas gave body of 'Gazan woman' not hostage Shiri Bibas: Netanyahu
10 hours ago | International
South Africa wins the toss, decides to bat against Afghanistan
South Africa wins the toss, decides to bat against Afghanistan
10 hours ago | Sports
Saudi Ambassador extends greetings in Bengali on Feb 21
Saudi Ambassador extends greetings in Bengali on Feb 21
8 hours ago | National