{"id":101911,"date":"2024-11-28T19:26:23","date_gmt":"2024-11-28T23:26:23","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=101911"},"modified":"2024-11-28T19:27:12","modified_gmt":"2024-11-28T23:27:12","slug":"north-korean-hackers-target-it-firms","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/north-korean-hackers-target-it-firms\/","title":{"rendered":"Report: North Korean Hackers Target IT Firms with Social Engineering Tactics"},"content":{"rendered":"\n<p>In recent years, the North Korean government (DPRK) has allegedly used numerous hacking groups, most notably the <a href=\"https:\/\/coinscreed.com\/staging\/lazarus-group-reportedly-behind-55m-coinex-hack.html\" target=\"_blank\" data-type=\"post\" data-id=\"59189\" rel=\"noreferrer noopener\">Lazarus Group<\/a>, to seal\u00a0crypto.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"900\" height=\"600\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics.webp\" alt=\"North Korean Hackers Target IT Firms with Social Engineering Tactics\" class=\"wp-image-101939\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics.webp 900w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-300x200.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-768x512.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-330x220.webp 330w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-420x280.webp 420w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-615x410.webp 615w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics-860x573.webp 860w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p>Hackers linked to the North Korean government have reportedly broadened their social engineering schemes to steal cryptocurrencies by infiltrating &#8220;hundreds&#8221; of multinational IT companies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">North Korean Hacking Groups Identified<\/h2>\n\n\n\n<p>At the Cyberwarcon cybersecurity conference, researchers highlighted two North Korean hacker groups, \u201cSapphire Sleet\u201d and \u201cRuby Sleet,\u201d according to a report by <a href=\"https:\/\/techcrunch.com\/2024\/11\/28\/north-korean-hackers-have-stolen-billions-in-crypto-by-posing-as-vcs-recruiters-and-it-workers\/?guccounter=1&guce_referrer=aHR0cHM6Ly9jb2ludGVsZWdyYXBoLmNvbS8&guce_referrer_sig=AQAAAA96BNyZ22Np1xx_Gh8mTSD0onlK9rB71tsa3xLLR59ELL2jnlZbBokgqVxGUrxZ8BJMCfSbM8N1Q60BKLczqny_vhtavh5TegerSosAweQs5_4_IJiUAS1emydcRAQ7Dr04QbykBC-8AHU1ot_ZlFb_BIN8TGeoxKG-7k1ullPB\" target=\"_blank\" rel=\"noreferrer noopener\">TechCrunch<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>Sapphire Sleet targeted individuals through fraudulent job schemes, pretending to be legitimate recruiters. <\/p>\n\n\n\n<p>They lured victims into interviews and then infected their computers with malware disguised as PDF files or malicious links during the recruitment process.<\/p>\n\n\n\n<p>Ruby Sleet focused on infiltrating aerospace and defense contractors in the United States, the United Kingdom, and South Korea to steal military secrets.<\/p>\n\n\n\n<p>The report also revealed that North Korean IT workers used AI-generated fake identities, social media profiles, and voice-altering technologies to infiltrate companies and execute recruitment scams.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"527\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9-1024x527.jpg\" alt=\"North Korean Hackers Target IT Firms with Social Engineering Tactics (2)\" class=\"wp-image-101938\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9-1024x527.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9-300x154.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9-768x395.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9-860x442.jpg 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/01937486-5eff-7126-9339-4da5df31e3a9.jpg 1114w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Crypto theft for November 2024. Source: Immunefi,\u00a0<\/em><a href=\"https:\/\/x.com\/BecauseBitcoin\/status\/1862143650840383812\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Because Bitcoin<\/em><span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Cryptocurrency Industry in the Crosshairs<\/h2>\n\n\n\n<p>Long before the Cyberwarcon findings, North Korean hackers had been targeting cryptocurrency firms with similar tactics.<\/p>\n\n\n\n<p>In August, blockchain investigator <a href=\"https:\/\/coinscreed.com\/staging\/zachxbt-says-21-north-korea-crypto-devs-make.html\" target=\"_blank\" rel=\"noreferrer noopener\">ZachXBT identified 21 developers<\/a>, allegedly North Korean, working on various crypto projects using fabricated identities.<\/p>\n\n\n\n<p>In September, the FBI warned that North Korean hackers were targeting crypto companies and decentralized finance (DeFi) projects. <\/p>\n\n\n\n<p>These attacks involved malware disguised as job offers, which stole users\u2019 private keys when downloaded or accessed through malicious links.<\/p>\n\n\n\n<p>In October, concerns arose within the Cosmos ecosystem over its Liquid Staking Module, reportedly developed by North Korean hackers. <\/p>\n\n\n\n<p>Jacob Gadikian, a Cosmos ecosystem developer, remarked, \u201cThe people who built the LSM are the world\u2019s most skilled and prolific crypto thieves.\u201d These fears prompted multiple security audits of the Liquid Staking Module to detect potential backdoors or harmful code.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In recent years, the North Korean government (DPRK) has allegedly used numerous hacking groups, most notably the Lazarus Group, to seal\u00a0crypto. Hackers linked to the North Korean government have reportedly broadened their social engineering schemes to steal cryptocurrencies by infiltrating &#8220;hundreds&#8221; of multinational IT companies. North Korean Hacking Groups Identified At the Cyberwarcon cybersecurity conference, [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":101939,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[202,15458,3964,12002,4337],"class_list":["post-101911","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-blockchain","tag-cybercrime-2","tag-cybersecurity","tag-hacks","tag-north-korea"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/North-Korean-Hackers-Target-IT-Firms-with-Social-Engineering-Tactics.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/101911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=101911"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/101911\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/101939"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=101911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=101911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=101911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}