Lazarus Group Hacks Crypto Talent Pool—Using U.S. Shell Companies as Bait
North Korea’s infamous Lazarus Group is at it again—this time, posing as legitimate U.S. firms to recruit and exploit blockchain developers. Because why bother with sanctions when you can just fake a Delaware LLC?
The playbook: Register glossy shell companies, post ’dream job’ listings for crypto talent, then siphon code—or worse. Another reminder that in Web3, if the offer looks too good to be true, it’s probably a nation-state attacker.
Bonus irony: These ops cost less than a single Wall Street exec’s annual coffee budget. Priorities.