Publish: 17:16, 29 Nov, 2024

North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros

Online Desk
North Korean hackers steal billions in crypto, posing as VCs, recruiters, IT pros
Symbolic

Security researchers have revealed a new dimension to North Korea’s cyber operations, involving imposters posing as venture capitalists, recruiters, and remote IT workers to steal cryptocurrency and corporate secrets. These efforts, they warn, have generated billions of dollars in stolen funds, helping the regime dodge international sanctions and fund its nuclear weapons program.

At Cyberwarcon, an annual cybersecurity conference in Washington, D.C., experts detailed the methods North Korean hackers use to infiltrate multinational corporations. James Elliott, a Microsoft security researcher, highlighted how North Korean IT workers have infiltrated "hundreds" of organizations globally, using false identities and U.S.-based intermediaries to bypass financial sanctions.

“North Korean IT workers are a triple threat,” Microsoft noted, referring to their ability to deceptively secure jobs, earn money for the regime, steal intellectual property, and extort their employers.

The researchers described a range of tactics employed by various North Korean hacking groups. One group, dubbed "Ruby Sleet" by Microsoft, targeted aerospace and defense companies to steal secrets for advancing weapons and navigation systems. Another group, "Sapphire Sleet," focused on cryptocurrency theft by impersonating recruiters and venture capitalists.

In fake venture capitalist schemes, the hackers lured victims into virtual meetings designed to fail, then pressured them to download malware disguised as troubleshooting tools. In fake recruitment efforts, victims were asked to complete a skills assessment, which also contained malware. This malware enabled hackers to access cryptocurrency wallets and other sensitive data. Microsoft reported that at least $10 million in cryptocurrency was stolen in just six months.

The most persistent threat comes from North Korean hackers taking advantage of the post-pandemic remote work boom. By securing remote jobs under false pretenses, they earn salaries that support the regime and gain access to sensitive company data.

Security firm KnowBe4 admitted earlier this year that it had unknowingly hired a North Korean operative. Once discovered, the company blocked the worker's access and confirmed no data was compromised. However, most victims remain silent, highlighting the challenges in addressing this growing threat.

North Korea’s cyber operations, described as a complex network of hacking groups with varying techniques but unified goals, face little international retaliation due to the country’s heavily sanctioned status. These activities underline the regime’s reliance on cybercrime to finance its ambitions while avoiding traditional economic constraints.

North Korean IT worker schemes have become increasingly sophisticated, with operatives creating online accounts such as LinkedIn profiles and GitHub pages to establish credibility, according to security researchers. Using AI technologies like face-swapping and voice-changing software, these workers craft elaborate false identities to secure remote jobs and further the regime’s agenda.

Once hired, companies unknowingly ship laptops to U.S.-based addresses managed by facilitators. These facilitators set up farms of company-issued devices, installing remote access software that allows North Korean operatives to log in from abroad, effectively masking their true locations. Microsoft noted that many of these operatives work not only from North Korea but also from allied nations like Russia and China, further complicating efforts to detect them.

Microsoft researcher James Elliott revealed the discovery of an inadvertently public repository linked to a North Korean IT worker, providing critical insights into the operation. The repository included dossiers, resumes, and spreadsheets detailing false identities and the profits generated by these campaigns. Elliott described the repository as containing the hackers' "entire playbooks," enabling a clearer understanding of their tactics.

To bolster the credibility of their fake personas, North Korean IT workers immediately verify their LinkedIn accounts as soon as they receive a company email address. However, researchers highlighted instances of sloppiness that exposed their true nature.

Hoi Myong and a researcher known as SttyK shared their methods for identifying suspected North Korean IT workers during a Cyberwarcon talk. In one case, they contacted an IT worker claiming to be Japanese but found linguistic errors in their communications, such as using phrases that don’t exist in the Japanese language. Other red flags included discrepancies in claimed locations and bank account details, such as having a Chinese account but an IP address tracing to Russia.

The U.S. government has imposed sanctions on North Korean-linked organizations involved in these schemes. The FBI has also warned about the use of AI-generated deepfake imagery to secure tech jobs. In 2024, prosecutors charged individuals involved in operating laptop farms used to bypass sanctions.

Despite these efforts, researchers emphasized that companies must improve their employee vetting processes. "They’re not going away," Elliott warned. "They’re gonna be here for a long time."

(Source: TechCrunch)

BD-Pratidin English/Mazdud

More News
Tesla launches in India with pricey $70,000 Model Y due to steep tariffs
Tesla launches in India with pricey $70,000 Model Y due to steep tariffs
After YouTube, Meta also declares war on copy-paste Facebook creators
After YouTube, Meta also declares war on copy-paste Facebook creators
Meta's Zuckerberg pledges hundreds of billions for AI data centers
Meta's Zuckerberg pledges hundreds of billions for AI data centers
Bitcoin tops $120,000 for the first time
Bitcoin tops $120,000 for the first time
Should ChatGPT give medical advice?
Should ChatGPT give medical advice?
Britain pledges to make electric cars cheaper to buy
Britain pledges to make electric cars cheaper to buy
Meet Aiman: AI Chef behind Dubai’s futuristic restaurant WOOHOO
Meet Aiman: AI Chef behind Dubai’s futuristic restaurant WOOHOO
WhatsApp solves group chat mystery with this new feature
WhatsApp solves group chat mystery with this new feature
SpaceX to invest $2bn in Musk's xAI startup
SpaceX to invest $2bn in Musk's xAI startup
Japan breaks internet speed world record
Japan breaks internet speed world record
China's Moonshot AI releases open-source model to reclaim market position
China's Moonshot AI releases open-source model to reclaim market position
Why has Elon Musk’s chatbot Grok been accused of anti-Semitism?
Why has Elon Musk’s chatbot Grok been accused of anti-Semitism?
Latest News
BB cuts reverse repo rate by 50 percent
BB cuts reverse repo rate by 50 percent
6 hours ago | Economy
14 NBR officials suspended for ‘publicly defying transfer orders’
14 NBR officials suspended for ‘publicly defying transfer orders’
7 hours ago | National
Dollar rebounds against taka after BB intervention
Dollar rebounds against taka after BB intervention
7 hours ago | Economy
Shanti's hattrick hands 3rd win for Bangladesh after venue change
Shanti's hattrick hands 3rd win for Bangladesh after venue change
8 hours ago | Sports
Canada keen to expand trade, investment in Bangladesh
Canada keen to expand trade, investment in Bangladesh
8 hours ago | City
State Mourning declared on July 16
State Mourning declared on July 16
8 hours ago | National
Ukrainians unimpressed by Trump's 50-day ultimatum to Putin
Ukrainians unimpressed by Trump's 50-day ultimatum to Putin
9 hours ago | International
Trump reportedly asked Zelensky if Ukraine could strike Moscow
Trump reportedly asked Zelensky if Ukraine could strike Moscow
9 hours ago | International
BSB Global Network chairman Bashar placed on 10-day remand
BSB Global Network chairman Bashar placed on 10-day remand
9 hours ago | City
Consensus reached on holding referendum for amending caretaker government provision: Ali Riaz
Consensus reached on holding referendum for amending caretaker government provision: Ali Riaz
9 hours ago | National
Archbishop invites Prof Yunus to attend interfaith dialogue in Sept
Archbishop invites Prof Yunus to attend interfaith dialogue in Sept
10 hours ago | National
Tarique Rahman stands by families of 10 martyrs in Kurigram
Tarique Rahman stands by families of 10 martyrs in Kurigram
10 hours ago | National
BNP firmly opposes PR system of elections
BNP firmly opposes PR system of elections
10 hours ago | National
Govt is prioritizing efforts to prevent erosion along the Teesta: Adviser Rizwana
Govt is prioritizing efforts to prevent erosion along the Teesta: Adviser Rizwana
11 hours ago | National
BNP alleges conspiracy to delay polls by destabilising law and order
BNP alleges conspiracy to delay polls by destabilising law and order
11 hours ago | National
Bangladesh team is not my family property: Salahuddin
Bangladesh team is not my family property: Salahuddin
11 hours ago | Sports
Rain halts Bangladesh-Bhutan clash after first half
Rain halts Bangladesh-Bhutan clash after first half
11 hours ago | Sports
Proud to stand with Bangladesh in empowering youth through skills: EU
Proud to stand with Bangladesh in empowering youth through skills: EU
11 hours ago | National
E-sports get as official 'Sport' recognition
E-sports get as official 'Sport' recognition
11 hours ago | Sports
Sohag murder: One more held
Sohag murder: One more held
11 hours ago | City
51 EC officials transferred at a time
51 EC officials transferred at a time
12 hours ago | National
None of 144 parties 'passed', get another 15 days
None of 144 parties 'passed', get another 15 days
12 hours ago | National
Dr Yunus doesn’t intend to be declared as "national reformer": Govt
Dr Yunus doesn’t intend to be declared as "national reformer": Govt
12 hours ago | National
8 NBR officials suspended for tearing up transfer letters
8 NBR officials suspended for tearing up transfer letters
12 hours ago | National
Palestinian MP killed in Israeli airstrike on Gaza City
Palestinian MP killed in Israeli airstrike on Gaza City
12 hours ago | International
Over 120 countries condemned Israel, US attacks on Iran
Over 120 countries condemned Israel, US attacks on Iran
13 hours ago | International
If we fail, it will be a collective failure: Ali Riaz
If we fail, it will be a collective failure: Ali Riaz
13 hours ago | National
55 lac families to receive rice at Tk15 per kg: Food Adviser
55 lac families to receive rice at Tk15 per kg: Food Adviser
14 hours ago | National
Muri Shinai De: The art of living well without pushing too hard
Muri Shinai De: The art of living well without pushing too hard
14 hours ago | Lifestyle
Netanyahu’s coalition is rattled as ultra-Orthodox party announces exit
Netanyahu’s coalition is rattled as ultra-Orthodox party announces exit
14 hours ago | International
Most Read
World War III has already begun — Russian researcher Dmitry Trenin
World War III has already begun — Russian researcher Dmitry Trenin
17 hours ago | International
Over Tk 2.5 lakh crore textile investment under threat
Over Tk 2.5 lakh crore textile investment under threat
18 hours ago | Special
3,554 murders, 4,105 rapes, 819 kidnappings in 10 months
3,554 murders, 4,105 rapes, 819 kidnappings in 10 months
17 hours ago | National
The challenge of Tk 14,000 crore Payra Port
The challenge of Tk 14,000 crore Payra Port
18 hours ago | Special
Taka rises fast – what’s causing the dollar to slip?
Taka rises fast – what’s causing the dollar to slip?
20 hours ago | Economy
Discord in Unity: Politicians Ignore Army Chief’s Call for Harmony
Discord in Unity: Politicians Ignore Army Chief’s Call for Harmony
17 hours ago | Special
Floodwater recedes, Tk43 lakh crop loss reported across 20 districts
Floodwater recedes, Tk43 lakh crop loss reported across 20 districts
21 hours ago | National
"Bangladesh must not be treated as a younger brother but as an equal"
"Bangladesh must not be treated as a younger brother but as an equal"
16 hours ago | National
Beyonce's unreleased music stolen from car
Beyonce's unreleased music stolen from car
18 hours ago | Showbiz
Govt to import 4 lakh tonnes of rice to avert food risk in flood season
Govt to import 4 lakh tonnes of rice to avert food risk in flood season
14 hours ago | National
Tarique under fire: BNP leaders decry targeted smear campaigns
Tarique under fire: BNP leaders decry targeted smear campaigns
17 hours ago | Special
Legendary singer Farida Parveen moved to cabin
Legendary singer Farida Parveen moved to cabin
19 hours ago | Showbiz
Iraqi patient plays oud, sings during brain tumour operation
Iraqi patient plays oud, sings during brain tumour operation
15 hours ago | Lifestyle
CA orders immediate appointment to vacant head teacher posts in pry school
CA orders immediate appointment to vacant head teacher posts in pry school
15 hours ago | National
Tax evasion tactics hidden behind charitable trusts
Tax evasion tactics hidden behind charitable trusts
18 hours ago | Economy
What it’s really like to live in 2025’s world’s best cities
What it’s really like to live in 2025’s world’s best cities
16 hours ago | Lifestyle
NBR’s ITIIU uncovers Tk1,874cr tax evasion in 7 months
NBR’s ITIIU uncovers Tk1,874cr tax evasion in 7 months
20 hours ago | Economy
'Bangladesh-South Korea FTA to foster deeper economic integration'
'Bangladesh-South Korea FTA to foster deeper economic integration'
20 hours ago | Economy
Bashundhara Kings join badminton league aiming to revive the sport
Bashundhara Kings join badminton league aiming to revive the sport
20 hours ago | Sports
Govt starts collecting uprising memories through 'Notes on July'
Govt starts collecting uprising memories through 'Notes on July'
15 hours ago | National
Launch, ferry movement halted on 10 Bhola routes
Launch, ferry movement halted on 10 Bhola routes
17 hours ago | National
Power deals signed under ousted AL govt to be reviewed: Finance adviser
Power deals signed under ousted AL govt to be reviewed: Finance adviser
15 hours ago | National
First image of Harry Potter released
First image of Harry Potter released
14 hours ago | Showbiz
French envoy upbeat about fair, inclusive polls in Bangladesh
French envoy upbeat about fair, inclusive polls in Bangladesh
20 hours ago | National
Bangladesh’s maiden antivenom project for Russell’s viper faces funding setback
Bangladesh’s maiden antivenom project for Russell’s viper faces funding setback
18 hours ago | National
Dhaka’s air continues to be ‘moderate’
Dhaka’s air continues to be ‘moderate’
19 hours ago | City
Meta's Zuckerberg pledges hundreds of billions for AI data centers
Meta's Zuckerberg pledges hundreds of billions for AI data centers
16 hours ago | Tech
Muri Shinai De: The art of living well without pushing too hard
Muri Shinai De: The art of living well without pushing too hard
14 hours ago | Lifestyle
Dubai bank consultant scammed out of Dh100,000 via WhatsApp trading scheme
Dubai bank consultant scammed out of Dh100,000 via WhatsApp trading scheme
18 hours ago | Economy
Around 14 million children received no vaccinations in 2024: UN
Around 14 million children received no vaccinations in 2024: UN
19 hours ago | International