Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

DeFi Planet2025/08/05 13:05
By: DeFi Planet
BTC+0.28%CLOUD0.00%
North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets.

North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets .

Cybersecurity researchers at Google Cloud and cloud security firm Wiz have both issued separate but aligned reports warning about the activities of UNC4899—also known as TraderTraitor—an advanced persistent threat group linked to North Korea’s military intelligence agency, the Reconnaissance General Bureau.

According to Google Cloud’s latest H2 2025 Cloud Threat Horizons Report , UNC4899 has been actively targeting the blockchain and cryptocurrency sectors since at least 2020, deploying highly refined social engineering tactics and exploiting cloud-specific vulnerabilities to breach organizations.

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets image 0 Google cloud report – Source: Google cloud

In two detailed incidents highlighted by Google, UNC4899 attackers posed as freelance recruiters on platforms like LinkedIn and Telegram. After establishing contact with employees, they convinced victims to run malicious Docker containers on their machines. These containers installed backdoors that gave the hackers access to internal systems.

Once inside, the attackers moved quickly—harvesting credentials, disabling multi-factor authentication (MFA), and identifying infrastructure connected to crypto wallets. In one case, after stealing millions in crypto assets via a compromised Google Cloud account, the attackers even re-enabled MFA to delay detection.

Wiz’s independent analysis corroborates Google’s findings, noting that UNC4899—also known under aliases like Jade Sleet, Slow Pisces, and TraderTraitor—shares overlapping techniques with other North Korean hacking groups such as Lazarus Group, BlueNoroff, and APT38.

The group reportedly shifted focus in 2023 toward using fake job offers as a primary vector of attack, specifically targeting employees at crypto exchanges and blockchain startups. Among their most devastating breaches are the $305 million heist from Japan’s DMM Bitcoin and the massive $1.5 billion Bybit attack in late 2024.

While exact figures vary, both Google and Wiz estimate UNC4899 alone has stolen tens of millions of dollars across multiple incidents. Chainalysis data shows North Korean-linked hackers looted $1.34 billion in crypto during 2024, while Wiz believes the figure has risen to $1.6 billion as of mid-2025.

 

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Crypto Market Faces Turmoil as Bitcoin Dives Below $104,000

In Brief Bitcoin and major altcoins saw significant drops, marking a "Bloody Friday." Key global events such as US-China relations heavily impacted the crypto market. Investors' confidence fell as the market lost approximately $500 billion last week.

Cointurk2025/10/18 13:39

Trending news

More
1
Crypto Market Faces Turmoil as Bitcoin Dives Below $104,000
2
3 Altcoins Built to Thrive Beyond Bitcoin’s Four-Year Cycle

Crypto prices

More
Bitcoin
Bitcoin
BTC
$106,861.07
+1.13%
Ethereum
Ethereum
ETH
$3,864.55
+2.26%
Tether USDt
Tether USDt
USDT
$1
+0.03%
BNB
BNB
BNB
$1,088.54
+2.18%
XRP
XRP
XRP
$2.37
+3.84%
Solana
Solana
SOL
$185.43
+3.04%
USDC
USDC
USDC
$0.9998
-0.01%
TRON
TRON
TRX
$0.3129
+1.60%
Dogecoin
Dogecoin
DOGE
$0.1872
+2.33%
Cardano
Cardano
ADA
$0.6317
+1.84%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter