North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report
Cyber operatives from North Korea infiltrated the US corporate system to launch a malware campaign aimed at crypto developers, Reuters reported Friday.According to US cybersecurity firm Silent Push, North Korean hackers...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Cyber operatives from North Korea infiltrated the US corporate system to launch a malware campaign aimed at crypto developers, Reuters reported Friday.
According to US cybersecurity firm Silent Push, North Korean hackers set up two companies, Blocknovas LLC and Softglide LLC, using fake names and addresses in New Mexico and New York.
Meanwhile, a third firm, Angeloper Agency, was also linked to the operation. However, it has not been officially registered in the country.
This campaign is tied to a subgroup within the Lazarus Group, a North Korean hacking unit under the Reconnaissance General Bureau, Pyongyang’s foreign intelligence agency.
Our team at Silent Push has been hard at work on the largest report we’ve ever made public – and along with Reuters – today we’re explaining how North Korean threat actors associated with the “Contagious Interview” subgroup created 3 front companies…
— Zach Edwards (@thezedwards) April 24, 2025 FBI Cracks Down on North Korea-Backed Crypto Scam Targeting DevelopersFurther, the FBI reportedly seized Blocknovas’ domain on Thursday, stating the action was part of a broader law enforcement effort against North Korean actors using fake job offers to distribute malware.
In its report, Reuters said the hackers use fake job interviews to trick developers into downloading malware designed to access crypto wallets and developer credentials.
Further, Reuters reviewed public records showing Blocknovas was registered to a vacant lot in South Carolina. Meanwhile, Softglide’s paperwork traced back to a small tax office in Buffalo. Silent Push said Blocknovas was the most active of the three front companies. It had already compromised multiple victims.
Collectively, these activities violate sanctions imposed by the US Treasury’s Office of Foreign Assets Control. They also breach UN measures designed to stop North Korea from funding its weapons programs through overseas businesses.
Crypto Theft and Covert IT Ops Fuel North Korea’s Military ExpansionThe incident adds to a growing list of sophisticated operations by Pyongyang targeting the crypto industry. These include sending thousands of IT workers abroad and carrying out high-profile cyber heists. The goal is to generate funds for North Korea’s nuclear ambitions.
Over the past few years, North Korea has increasingly turned to crypto-related crimes to raise funds. Notably, it has been linked to a string of high-profile thefts, including the 2022 Axie Infinity hack.
Parallely, the regime has also sent thousands of IT workers overseas. These workers are said to secretly send their earnings back to the state. Moreover, these activities are believed to support North Korea’s weapons program. Reports say stolen crypto assets have helped fund its ballistic missile development.
The post North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report appeared first on Cryptonews.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO
Bitcoin Magazine North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO Hackers from North Korea targeted crypto e...
Tokenized iShares MSCI South Korea ETF Arrives on StonkFun for Solana Coin Launches
Key Takeaways: StonkFun now supports coin launches paired with $EWY, the tokenized iShares MSCI South Korea ETF. Overall, the inte...
Crypto Hacks: Three Projects Hacked in One Day as Losses Hit Over $11M
Three crypto projects were attacked on September 24, suffering combined losses of more than $11M. Attackers drained around $1.8M f...
XRP News: Bitget Hacker Moves 54M XRP, Putting Fresh Selling Pressure
The attacker behind Bitget’s $388 million news driver has moved about 54 million stolen XRP out of three of the five wallets that...
Bitget’s hack just got $36 million bigger, and now there’s a bounty on the stolen crypto
Bitget has raised the estimated value of assets taken in its Sept. 24 breach to $387.5 million as exchanges and security firms mob...
DeFi hack attack: Three exploits snatch $11M in a single day
Crypto and DeFi projects continue to be hacked at a dizzying pace, and few days in recent weeks have been incident-free. That said...