No Result
View All Result
Tuesday, July 15, 2025
  • Login
  • News
    • Bitcoin News
    • Altcoin News
    • Crypto News
    • NFT News
  • Cryptocurrency
    • Price Predictions
    • Crypto Education
    • Features
  • Advertise
    • Submit Your PR
    • Press Release
  • About
    • About Us
    • Editorial Policy
    • Privacy Policy
    • Careers
    • Contact Us
  • News
    • Bitcoin News
    • Altcoin News
    • Crypto News
    • NFT News
  • Cryptocurrency
    • Price Predictions
    • Crypto Education
    • Features
  • Advertise
    • Submit Your PR
    • Press Release
  • About
    • About Us
    • Editorial Policy
    • Privacy Policy
    • Careers
    • Contact Us
No Result
View All Result
No Result
View All Result

North Korean Hackers Set Up Fake U.S. Companies to Target Crypto Developers

Haider Ali by Haider Ali
3 months ago
in Crypto News
0
North Korean Hackers Set Up Fake U.S. Companies to Target Crypto Developers
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter
  • Lazarus hackers used fake U.S. firms to lure crypto developers.
  • Malware was spread via Zoom, GitHub, and NPM.
  • FBI intervened, but attacks are still ongoing.

According to a new cybersecurity firm, Silent Push investigation, the North Korean state-backed Lazarus Group and its associated advanced persistent threat (APT) subgroup known as Contagious Interview are behind increasingly sophisticated cyberattacks targeting the cryptocurrency sector.

Lazarus Group Hacks Crypto with Fake Firms

According to the report, hackers affiliated with the Lazarus Group have resorted to various tricks to infiltrate the crypto ecosystem. This includes exploiting Zoom job interviews, embedding malware inside GitHub repositories and NPM packages and, most importantly, companies set up with fake but legally registered in the United States. Researchers have found a handful of examples where attackers went to such lengths to entice crypto developers and take over their systems with data-stealing malware, though establishing a legitimate U.S. business entity to do that remains one of the most difficult.

Despite having fabricated identities and addresses, the two companies, Blocknovas LLC registered in New Mexico and Softglide LLC, registered in New York, were built according to the results of the Silent Push analysis. The firm’s report lists the false credentials used in the campaign. 

Source: Silent Push

According to researchers, another entity associated with the theft, Angeloper Agency, does not appear to be officially registered in the United States. Blocknovas is reported to be the most active front company used in the malicious operation of the three.

Kasey Best, Director of Threat Intelligence at Silent Push, told Reuters, “This is a rare instance in that the North Korean hackers actually use legitimate corporate entities in the U.S., and setting up corporate fronts in a U.S. jurisdiction to attack unsuspecting job applicants.”

These attacks follow the previous report’s scheme, where cybercriminals pretended to be legitimate employers during fake video interviews. Last month, Nick Bax of the Security Alliance revealed that one such threat group hires crypto developers over the phone using Zoom. 

Having audio issues on your Zoom call? That's not a VC, it's North Korean hackers.

Fortunately, this founder realized what was going on.

The call starts with a few "VCs" on the call. They send messages in the chat saying they can't hear your audio, or suggesting there's an… pic.twitter.com/ZnW8Mtof4F

— Nick Bax.eth (@bax1337) March 11, 2025

Attacks during these sessions involved attackers posing as technical issues, and instructing their victims to click on malicious links, which reportedly have ‘stolen tens of millions of dollars.’ Bax said other bad actors are replicating the method.

The Contagious Interview subgroup is another reason Silent Push points out as contributing to this new campaign. These fraudulent interviews lead him to note that these people load their computers with extremely sophisticated malware to steal developers’ cryptocurrency wallets and pilfering credentials that could otherwise be used for secondary attacks on legitimate businesses. In the latest campaign, the firm has confirmed multiple victims.

Contagious Interview Subgroup Behind New Campaign

This comes amid a broader law enforcement effort to take down North Korean cyber infrastructure, as the FBI has also intervened by seizing the domain linked to Blocknovas LLC. It said the domain was used to send malware and fraudulent job postings to mislead individuals. Despite the seizure, the Softglide LLC and Angeloper Agency websites are up as of the reporting time.

Adding another level of worry, Lazarus Group operatives have further attempted to inject malicious JavaScript code into GitHub repositories and NPM packages. 

The second alleged campaign is believed to have started in August 2024 and continues. In this vector, the malware used is Marstech1 that specifically targets well known cryptocurrency wallets such as MetaMask, Exodus and Atomic.

Between September 2024 and Jan 2025 cybersecurity company SecurityScorecard found 233 who installed Marstech1 malware by accident. New variants and techniques continue to appear in the attack campaign, and it is active.

Silent Push’s research provides an ominous view of the changing face of the threat landscape for the crypto industry, showing how North Korean cyber operatives have pushed tactics to become more sophisticated and deceptive to penetrate defences and steal digital assets.

Tags: Crypto SecurityFBI InvestigationLazarus GroupMalware AlertNorth Korea Hacks
Haider Ali

Haider Ali

Haider Ali is a seasoned crypto journalist known for delivering insightful analysis and breaking news in the blockchain and cryptocurrency space. His work is featured in leading industry publications, earning him a reputation as a trusted voice in the crypto community.

  • Trending
  • Comments
  • Latest
ASIC Shuts Down 95 Crypto and Romance Scam Firms Linked to $35M Losses

ASIC Shuts Down 95 Crypto and Romance Scam Firms Linked to $35M Losses

April 8, 2025
Whale Snaps Up $1.7M in AVA, Eyes Long-Term Gains

Whale Snaps Up $1.7M in AVA, Eyes Long-Term Gains

May 3, 2025
Altcoin Shows Mixed Signals Amid Tariff Tensions and Fed’s Crash Warning

Altcoin Shows Mixed Signals Amid Tariff Tensions and Fed’s Crash Warning

April 7, 2025
Binance Founder CZ Appointed Strategic Adviser to Pakistan Crypto Council

Binance Founder CZ Appointed Strategic Adviser to Pakistan Crypto Council

April 8, 2025
Why Is Bitcoin Dropping Today?

Why Is Bitcoin Dropping Today?

0
Altcoin Shows Mixed Signals Amid Tariff Tensions and Fed’s Crash Warning

Altcoin Shows Mixed Signals Amid Tariff Tensions and Fed’s Crash Warning

0
Crypto Market Crash Amid Tariff Shock and Global Sell-Off

Crypto Market Crash Amid Tariff Shock and Global Sell-Off

0
Trump Launches $99 NFT Collection Featuring Superhero and Bitcoin Themes

Trump Launches $99 NFT Collection Featuring Superhero and Bitcoin Themes

0
FTX Fights $1.53B Claim From 3AC Collapse

FTX Fights $1.53B Claim From 3AC Collapse

June 24, 2025
PEPE Price Analysis for June 11

PEPE Price Analysis for June 11

June 11, 2025
Lagrange Token Skyrockets 528% Following Major Exchange Listings

Lagrange Token Skyrockets 528% Following Major Exchange Listings

June 5, 2025
Bitcoin Gains Traction as U.S. Struggles with Soaring Deficit

Bitcoin Gains Traction as U.S. Struggles with Soaring Deficit

June 4, 2025

Recent News

FTX Fights $1.53B Claim From 3AC Collapse

FTX Fights $1.53B Claim From 3AC Collapse

June 24, 2025
PEPE Price Analysis for June 11

PEPE Price Analysis for June 11

June 11, 2025

Categories

  • Altcoin News
  • Bitcoin News
  • Crypto Education
  • Crypto News
  • Features
  • News
  • NFT News
  • Price Predictions

Site Navigation

  • About Us
  • Contact Us
  • Editorial Policy
  • Privacy Policy
  • Careers
  • Disclaimer
  • Terms and Conditions
AltcoinBreaking

AltcoinBreaking delivers breaking crypto news and analysis on Bitcoin, Ethereum, Altcoins, Blockchain, NFTs, and the latest crypto market trends.

DISCLAIMER: The content published on AltcoinBreaking is for informational purposes only and does not constitute financial or investment advice. Cryptocurrencies are highly volatile, and we recommend conducting your own research and consulting a financial advisor before making any decisions. AltcoinBreaking is not responsible for any losses or damages resulting from the use of the information on this website. Please note that content published in the Press Release category is provided by third parties for promotional purposes and is not written by our staff. AltcoinBreaking does not guarantee the accuracy or authenticity of PR content. We encourage you to conduct your own research before acting on any information presented in this category.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • News
    • Bitcoin News
    • Altcoin News
    • Crypto News
    • NFT News
  • Cryptocurrency
    • Price Predictions
    • Crypto Education
    • Features
  • Advertise
    • Submit Your PR
    • Press Release
  • About
    • About Us
    • Editorial Policy
    • Privacy Policy
    • Careers
    • Contact Us

DISCLAIMER: The content published on AltcoinBreaking is for informational purposes only and does not constitute financial or investment advice. Cryptocurrencies are highly volatile, and we recommend conducting your own research and consulting a financial advisor before making any decisions. AltcoinBreaking is not responsible for any losses or damages resulting from the use of the information on this website. Please note that content published in the Press Release category is provided by third parties for promotional purposes and is not written by our staff. AltcoinBreaking does not guarantee the accuracy or authenticity of PR content. We encourage you to conduct your own research before acting on any information presented in this category.