Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Tracking & Law Enforcement

FBI: North Korea Aggressively Hacking Cryptocurrency Firms

The FBI warns of North Korean threat actors conducting social engineering campaigns targeting employees in the cryptocurrency industry.

North Korea hackers

North Korean hackers are aggressively targeting the cryptocurrency industry, using sophisticated social engineering to achieve their goals, the Federal Bureau of Investigation warns.

The purpose of the attacks, the FBI advisory shows, is to deploy malware and steal virtual assets from decentralized finance (DeFi), cryptocurrency, and similar entities.

“North Korean social engineering schemes are complex and elaborate, often compromising victims with sophisticated technical acumen. Given the scale and persistence of this malicious activity, even those well versed in cybersecurity practices can be vulnerable,” the FBI says.

According to the agency, North Korean threat actors are conducting extensive research on prospective victims associated with DeFi or cryptocurrency-related businesses, and then target them with individualized fake scenarios, typically involving new employment or corporate investments.

The attackers also engage in prolonged conversations with the intended victims, to establish trust before delivering malware “in situations that may appear natural and non-alerting”.

Furthermore, the threat actors often impersonate various individuals, including contacts that the victim may know, using realistic imagery, such as photos stolen from social media accounts, and fake images of time sensitive events.

Advertisement. Scroll to continue reading.

According to the FBI, North Korean threat actors have been observed conducting research on targets connected to cryptocurrency exchange-traded funds (ETFs), which suggests they could start targeting these entities.

Individuals associated with the crypto industry should be aware of requests to run code or applications on company-owned devices, requests to conduct tests or exercises involving non-standard code packages, offers of employment or investment, requests to move conversations to other messaging platforms, and unsolicited contacts containing links or attachments.

Organizations are advised to develop means of verifying a contact’s identity, to refrain from sharing information about cryptocurrency wallets, avoid taking pre-employment tests or running code on company-owned devices, implement multi-factor authentication, use closed platforms for business communication, and limit access to sensitive network documentation and code repositories.

Social engineering, however, is only one of the techniques that North Korean hackers employ in attacks targeting cryptocurrency organizations, Mandiant notes in a new report.

The attackers were also seen relying on supply chain attacks to deploy malware and then pivot to other resources. They may also target smart contracts (either via reentrancy attacks or flash loan attacks) and decentralized autonomous organizations (via governance attacks), the Google-owned security firm explains. 

Related: Microsoft Says North Korean Cryptocurrency Thieves Behind Chrome Zero-Day

Related: Hackers Steal Over $2 Million in Cryptocurrency From CoinStats Wallets

Related: North Korean Hackers Hijack Antivirus Updates for Malware Delivery

Related: Euler Loses Nearly $200 Million to Flash Loan Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.