Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets

DeFi PlanetDeFi Planet2025/08/05 13:05
By:DeFi Planet

North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets.

North Korean threat actors are ramping up a sophisticated campaign of cyber theft targeting the cryptocurrency industry, using fake identities and remote job scams to infiltrate firms and siphon off millions of dollars in digital assets .

Cybersecurity researchers at Google Cloud and cloud security firm Wiz have both issued separate but aligned reports warning about the activities of UNC4899—also known as TraderTraitor—an advanced persistent threat group linked to North Korea’s military intelligence agency, the Reconnaissance General Bureau.

According to Google Cloud’s latest H2 2025 Cloud Threat Horizons Report , UNC4899 has been actively targeting the blockchain and cryptocurrency sectors since at least 2020, deploying highly refined social engineering tactics and exploiting cloud-specific vulnerabilities to breach organizations.

North Korean Hackers Infiltrate Crypto Firms Using Fake Job Scams, Steal Millions in Digital Assets image 0 Google cloud report – Source: Google cloud

In two detailed incidents highlighted by Google, UNC4899 attackers posed as freelance recruiters on platforms like LinkedIn and Telegram. After establishing contact with employees, they convinced victims to run malicious Docker containers on their machines. These containers installed backdoors that gave the hackers access to internal systems.

Once inside, the attackers moved quickly—harvesting credentials, disabling multi-factor authentication (MFA), and identifying infrastructure connected to crypto wallets. In one case, after stealing millions in crypto assets via a compromised Google Cloud account, the attackers even re-enabled MFA to delay detection.

Wiz’s independent analysis corroborates Google’s findings, noting that UNC4899—also known under aliases like Jade Sleet, Slow Pisces, and TraderTraitor—shares overlapping techniques with other North Korean hacking groups such as Lazarus Group, BlueNoroff, and APT38.

The group reportedly shifted focus in 2023 toward using fake job offers as a primary vector of attack, specifically targeting employees at crypto exchanges and blockchain startups. Among their most devastating breaches are the $305 million heist from Japan’s DMM Bitcoin and the massive $1.5 billion Bybit attack in late 2024.

While exact figures vary, both Google and Wiz estimate UNC4899 alone has stolen tens of millions of dollars across multiple incidents. Chainalysis data shows North Korean-linked hackers looted $1.34 billion in crypto during 2024, while Wiz believes the figure has risen to $1.6 billion as of mid-2025.

 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!