Close Menu
CryptoHoppers.comCryptoHoppers.com
    What's Hot

    The Art of Interpretation: Understanding and Applying the Death Cross in Crypto Trading

    March 7, 2024

    Building Trust in Crypto: How to Establish Your Project as a Reliable Source

    May 16, 2024

    Ripple boss sheds light on SEC and Hinman’s internal documents

    June 18, 2023
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Get In Touch
    Facebook X (Twitter) Instagram
    CryptoHoppers.comCryptoHoppers.com
    • News

      Bybit Launches Byreal DEX – Is This the Start of a DeFi Pivot?

      June 15, 2025

      8,000 Bitcoins awaken after 5 years – Whale strategy or ETF play?

      June 14, 2025

      Bitcoin’s High Euphoria Spurs UK Company’s $4.7 Million Buy

      June 12, 2025

      Why are altcoins like Axelar, Aave, Uniswap, Pepe going up today?

      June 10, 2025

      XRP Price Watch: RSI Neutral, MACD Turns Bullish in a Tight Range Battle

      June 9, 2025
    • Technology

      Ripple And Japan’s Web3 Salon Spark Asia Innovation

      June 15, 2025

      Small caps, big moves: These altcoins outshine Bitcoin

      June 14, 2025

      Comment on Hacker Behind $2M Crypto Hack Offered Role by Targeted Protocol by James Cyrus

      June 13, 2025

      Uniswap (UNI) Gears for Rally as $10.35 Resistance Becomes Make-or-Break Level

      June 12, 2025

      The Blockchain Group Pushes Institutional Crypto Wave in Europe

      June 11, 2025
    • Learn/Guide

      Bybit to launch Byreal, its first onchain DEX on Solana, on June 30

      June 15, 2025

      Invesco, Galaxy Digital file to launch Solana ETF in Delaware amid SEC approval buzz

      June 14, 2025

      Cardano founder Charles Hoskinson proposes converting $100M ADA to Bitcoin and stablecoins

      June 13, 2025

      BlackRock targets to become world’s largest crypto asset manager by 2030

      June 12, 2025

      Nasdaq-listed Interactive Strength plans to invest $500M in Fetch.ai’s FET token to build an AI-focused crypto treasury

      June 11, 2025
    • NFTs

      1mouth Analog: miirror’s Raw Leap from Digital to Handmade Chaos | NFT CULTURE | NFT News | Web3 Culture

      May 9, 2025

      NFTCulture Expands Into TCGs with Cardcore.xyz: Where Digital Collectibles Meet Competitive Play | NFT CULTURE | NFT News | Web3 Culture

      May 8, 2025

      From Moonshots to Broken Links: The Rise and Fall of CloneX | NFT CULTURE | NFT News | Web3 Culture

      April 24, 2025

      Pacific Spirit: Vinyl Meets Code in a Groundbreaking Generative Drop on Art Blocks | NFT CULTURE | NFT News | Web3 Culture

      April 16, 2025

      Daizen: Elevating the NFT Multiverse on Apechain Blockchain | NFT CULTURE | NFT News | Web3 Culture

      December 5, 2024
    • Regulation

      SEC Drops Binance Lawsuit: How Regulatory Clarity Could Spark a BNB Price Rally

      May 30, 2025

      Kentucky Governor Signs Off On ‘Bitcoin Rights’ Bill, Strengthening Crypto Protections

      March 31, 2025

      Utah Moves Closer To Bitcoin Reserve As Bill Advances To Senate Standing Committee

      February 23, 2025

      Bitcoin ETFs In Focus As Kansas Senator Proposes Up To 10% Pension Fund Allocation

      January 26, 2025

      MicroStrategy May Face Tax Issues Over $19 Billion Unrealized Bitcoin Gains: Report

      January 25, 2025
    • Business

      Sri Lanka’s E-commerce Platform Kapruka to Introduce Crypto Payments

      November 17, 2024

      Leading Eastern European Exchange Exmo Sells Business in Russia, Belarus

      November 16, 2024

      Bank of Russia to Launch Digital Ruble Payment Infrastructure by July 2025

      November 15, 2024

      Bitcoin Mining Company Mara Holdings Now Holds 26,747 Bitcoin: Q3 Earnings Report Reveals

      November 14, 2024

      Brazil Prepares to Let Tradfi Institutions Embrace Crypto

      November 13, 2024
    • Live Pricing
    CryptoHoppers.comCryptoHoppers.com
    Home » North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets
    Learn/Guide

    North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets

    April 25, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Key Takeaways

    • Lazarus Group set up fake US companies to target crypto industry developers with malware.
    • The operation represents an evolution in North Korea’s efforts to target the crypto sector for funding.

    Share this article







    North Korea’s Lazarus Group, through its subunit, spun up fake US-registered companies as part of a campaign to phish crypto developers and steal their wallets, according to a new report from Reuters.

    The companies, Blocknovas LLC and Softglide LLC, were registered in New Mexico and New York using fake personas and addresses. Another entity, Angeloper Agency, is reportedly connected to the operation, but it is not registered in the US.

    The scheme

    The tactics involved creating fake companies, establishing a convincing online presence, and posting job listings targeting developers.

    Hackers used false identities, made-up addresses, and real platforms like LinkedIn and Upwork to appear legitimate and attract developers. Once applicants opted in, they were taken through fake interviews and instructed to download test assignments or software.

    These files contained malware that, once executed, gave attackers access to the victim’s system, allowing them to extract passwords, crypto wallet keys, and other sensitive data.

    Russian-speaking group used nearly identical tactics in earlier campaign

    In February, BleepingComputer reported that Crazy Evil, a Russian-speaking cybercrime group, had already deployed comparable tactics in a targeted scam against crypto and web3 job seekers.

    A subgroup of Crazy Evil created a fake company called ChainSeeker.io, posting fraudulent listings on platforms like LinkedIn. Applicants were directed to download a malicious app, GrassCall, which installed malware designed to steal credentials, crypto wallets, and sensitive files.

    The operation was well-coordinated, using cloned websites, fake profiles, and Telegram to distribute malware.

    FBI confirms North Korean link

    Kasey Best, director of threat intelligence at Silent Push, said this is one of the first known cases of North Korean hackers setting up legally registered companies in the US to bypass scrutiny and gain credibility.

    Silent Push traced the hackers back to the Lazarus Group and confirmed multiple victims of the campaign, identifying Blocknovas as the most active of the three front companies they uncovered.  

    The FBI seized Blocknovas’ domain as part of enforcement actions against North Korean cyber actors who used fake job postings to distribute malware.

    FBI officials said they continue to “focus on imposing risks and consequences, not only on the DPRK actors themselves, but anybody who is facilitating their ability to conduct these schemes.”

    According to an FBI official, North Korean cyber operations are among the nation’s most sophisticated persistent threats.

    North Korea leverages Russian infrastructure to scale attacks

    To overcome limited domestic internet access, North Korea’s hacking group uses international infrastructure, particularly Russian IP ranges hosted in Khasan and Khabarovsk, towns with direct ties to North Korea, according to an in-depth analysis from Trend Micro.

    Using VPNs, RDP sessions, and proxy services like Astrill VPN and CCProxy, Lazarus operatives are able to manage attacks, communicate via GitHub and Slack, and access platforms such as Upwork and Telegram.

    Researchers at Silent Push have identified seven instructional videos recorded by accounts linked to BlockNovas as part of the operation. The videos describe how to set up command-and-control servers, steal passwords from browsers, upload stolen data to Dropbox, and crack crypto wallets with tools such as Hashtopolis.

    From theft to state-sponsored espionage

    Hundreds of developers have been targeted, with many unknowingly exposing their sensitive credentials. Some breaches appear to have escalated beyond theft, suggesting Lazarus may have handed over access to other state-aligned teams for espionage purposes.

    US, South Korean, and UN officials have confirmed to Reuters that North Korea’s hackers have deployed thousands of IT workers overseas to generate millions in funding for Pyongyang’s nuclear missile program.

    Share this article









    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bybit to launch Byreal, its first onchain DEX on Solana, on June 30

    June 15, 2025

    Invesco, Galaxy Digital file to launch Solana ETF in Delaware amid SEC approval buzz

    June 14, 2025

    Cardano founder Charles Hoskinson proposes converting $100M ADA to Bitcoin and stablecoins

    June 13, 2025

    BlackRock targets to become world’s largest crypto asset manager by 2030

    June 12, 2025
    Top Posts

    My Neighbor Alice: Bridging Traditional Gaming & Web3 Through Cozy Island Building

    November 27, 2024

    Blockchain Powered Immuno-Oncology Company Mateon Claims Anti-Malarial Drug Called Artemisinin, Derived from Asian Medicine Can Help Fight Covid-19

    June 18, 2023

    “Mysterious” $31 Million Bitcoin Donation to Silk Road Founder Ross Ulbricht Suspected to Originate from AlphaBay

    June 7, 2025

    Welcome to CryptoHoppers.com! Stay informed with the latest updates, trends, and insights from the dynamic world of cryptocurrencies. From Bitcoin to altcoins, blockchain technology to decentralized finance (DeFi), we cover it all. Discover expert analysis, market trends, regulatory developments, and exciting innovations shaping the crypto industry.

    Top Insights

    Bybit Launches Byreal DEX – Is This the Start of a DeFi Pivot?

    June 15, 2025

    8,000 Bitcoins awaken after 5 years – Whale strategy or ETF play?

    June 14, 2025

    Bitcoin’s High Euphoria Spurs UK Company’s $4.7 Million Buy

    June 12, 2025
    Advertisement
    Demo
    CryptoHoppers.com
    Facebook X (Twitter) Instagram
    • News
    • Technology
    • Learn/Guide
    • Regulation
    • NFTs
    • Business
    • Live Pricing
    © 2025. Designed by CryptoHoppers.com.

    Type above and press Enter to search. Press Esc to cancel.