Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

DeFi Planet2025/08/05 13:05
By: DeFi Planet
BTC+0.04%CLOUD0.00%
North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets.

North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets .

Cybersecurity researchers at Google Cloud and cloud security firm Wiz have both issued separate but aligned reports warning about the activities of UNC4899—also known as TraderTraitor—an advanced persistent threat group linked to North Korea’s military intelligence agency, the Reconnaissance General Bureau.

According to Google Cloud’s latest H2 2025 Cloud Threat Horizons Report , UNC4899 has been actively targeting the blockchain and cryptocurrency sectors since at least 2020, deploying highly refined social engineering tactics and exploiting cloud-specific vulnerabilities to breach organizations.

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets image 0 Google cloud report – Source: Google cloud

In two detailed incidents highlighted by Google, UNC4899 attackers posed as freelance recruiters on platforms like LinkedIn and Telegram. After establishing contact with employees, they convinced victims to run malicious Docker containers on their machines. These containers installed backdoors that gave the hackers access to internal systems.

Once inside, the attackers moved quickly—harvesting credentials, disabling multi-factor authentication (MFA), and identifying infrastructure connected to crypto wallets. In one case, after stealing millions in crypto assets via a compromised Google Cloud account, the attackers even re-enabled MFA to delay detection.

Wiz’s independent analysis corroborates Google’s findings, noting that UNC4899—also known under aliases like Jade Sleet, Slow Pisces, and TraderTraitor—shares overlapping techniques with other North Korean hacking groups such as Lazarus Group, BlueNoroff, and APT38.

The group reportedly shifted focus in 2023 toward using fake job offers as a primary vector of attack, specifically targeting employees at crypto exchanges and blockchain startups. Among their most devastating breaches are the $305 million heist from Japan’s DMM Bitcoin and the massive $1.5 billion Bybit attack in late 2024.

While exact figures vary, both Google and Wiz estimate UNC4899 alone has stolen tens of millions of dollars across multiple incidents. Chainalysis data shows North Korean-linked hackers looted $1.34 billion in crypto during 2024, while Wiz believes the figure has risen to $1.6 billion as of mid-2025.

 

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

SEC Faces Deadline for Grayscale XRP ETF Decision
TheCryptoUpdates2025/10/18 23:54
Ethereum Bulls Remain Unfazed: Analyzing Market Confidence After $232 Million Liquidation

Ethereum’s price is fluctuating around $3,700, influenced by US credit and labor data, with traders cautiously avoiding high leverage. Whale activity indicates limited bearish sentiment, but there is insufficient confidence in a rapid rebound. No warning signals have been observed in the derivatives market, and a recovery will require clearer macroeconomic signals. Summary generated by Mars AI. This summary is produced by the Mars AI model, and the accuracy and completeness of its content are still being iteratively updated.

MarsBit2025/10/18 22:32
BNY Mellon Empowers Crypto Ecosystem with Robust Infrastructure

In Brief BNY Mellon enhances its crypto ecosystem role through infrastructure services, not its own coin. The bank supports stablecoin projects instead of launching an altcoin amid positive market conditions. BNY Mellon prioritizes infrastructure over token issuance, promoting collaboration and ecosystem strength.

Cointurk2025/10/18 21:27

Trending news

More
1
Astra Nova claims to have been hacked and had its assets dumped, while some users suspect insider theft.
2
SEC Faces Deadline for Grayscale XRP ETF Decision

Crypto prices

More
Bitcoin
Bitcoin
BTC
$107,308.49
+0.16%
Ethereum
Ethereum
ETH
$3,903.28
+0.77%
Tether USDt
Tether USDt
USDT
$1
-0.00%
BNB
BNB
BNB
$1,091.65
+0.03%
XRP
XRP
XRP
$2.36
+1.03%
Solana
Solana
SOL
$186.91
+1.06%
USDC
USDC
USDC
$1
+0.04%
TRON
TRON
TRX
$0.3141
+0.49%
Dogecoin
Dogecoin
DOGE
$0.1904
+1.78%
Cardano
Cardano
ADA
$0.6345
+0.32%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter