North Korean Hackers Target Crypto Firms with Fake Job Offers, Steal $1.6B
North Korean hacking groups have refined their tactics to infiltrate cloud systems and pilfer cryptocurrencies, according to joint research from Google Cloud and cybersecurity firm Wiz. The campaign, dubbed TraderTraitor, has evolved since 2020 to deploy AI-generated lures and malware against digital asset companies.
Google's Threat Intelligence Group reports that hacking unit UNC4899 successfully compromised two organizations by posing as freelance employers. After establishing contact through social media, the group assigned tasks that triggered malware infections, granting access to corporate cloud environments. This enabled theft of credentials and identification of crypto transaction hosts.
The operation reflects Pyongyang's growing sophistication in cybercrime, having stolen $1.6 billion in digital assets this year alone. Security analysts note the attacks demonstrate scalable infrastructure capable of bypassing traditional defense mechanisms.