• bitcoinBitcoin (BTC) $ 113,795.00
  • ethereumEthereum (ETH) $ 3,585.39
  • xrpXRP (XRP) $ 2.95
  • tetherTether (USDT) $ 0.999807
  • bnbBNB (BNB) $ 750.23
  • solanaSolana (SOL) $ 163.17
  • usd-coinUSDC (USDC) $ 0.999800
  • staked-etherLido Staked Ether (STETH) $ 3,582.64
  • tronTRON (TRX) $ 0.332003
  • dogecoinDogecoin (DOGE) $ 0.198907
  • cardanoCardano (ADA) $ 0.722203
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,844.00
  • wrapped-stethWrapped stETH (WSTETH) $ 4,336.36
  • hyperliquidHyperliquid (HYPE) $ 38.13
  • stellarStellar (XLM) $ 0.395903
  • suiSui (SUI) $ 3.40
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,851.97
  • chainlinkChainlink (LINK) $ 16.31
  • bitcoin-cashBitcoin Cash (BCH) $ 548.24
  • hedera-hashgraphHedera (HBAR) $ 0.237995
  • wrapped-eethWrapped eETH (WEETH) $ 3,846.30
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • avalanche-2Avalanche (AVAX) $ 21.72
  • litecoinLitecoin (LTC) $ 120.30
  • wethWETH (WETH) $ 3,586.80
  • leo-tokenLEO Token (LEO) $ 8.98
  • usdsUSDS (USDS) $ 0.999498
  • the-open-networkToncoin (TON) $ 3.23
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999691
  • whitebitWhiteBIT Coin (WBT) $ 42.72
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 113,835.00
  • uniswapUniswap (UNI) $ 9.49
  • polkadotPolkadot (DOT) $ 3.60
  • moneroMonero (XMR) $ 292.32
  • bitget-tokenBitget Token (BGB) $ 4.29
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • crypto-com-chainCronos (CRO) $ 0.136197
  • pepePepe (PEPE) $ 0.000010
  • aaveAave (AAVE) $ 253.85
  • ethenaEthena (ENA) $ 0.579988
  • daiDai (DAI) $ 0.999792
  • bittensorBittensor (TAO) $ 338.59
  • ethereum-classicEthereum Classic (ETC) $ 20.06
  • mantleMantle (MNT) $ 0.897303
  • nearNEAR Protocol (NEAR) $ 2.43
  • ondo-financeOndo (ONDO) $ 0.917410
  • aptosAptos (APT) $ 4.23
  • okbOKB (OKB) $ 45.06
  • internet-computerInternet Computer (ICP) $ 5.03
  • pi-networkPi Network (PI) $ 0.344230
  • jito-staked-solJito Staked SOL (JITOSOL) $ 199.30
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • kaspaKaspa (KAS) $ 0.085775
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,586.60
  • usd1-wlfiUSD1 (USD1) $ 0.999586
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.033499
  • algorandAlgorand (ALGO) $ 0.236624
  • fasttokenFasttoken (FTN) $ 4.58
  • arbitrumArbitrum (ARB) $ 0.382383
  • vechainVeChain (VET) $ 0.022784
  • gatechain-tokenGate (GT) $ 16.32
  • cosmosCosmos Hub (ATOM) $ 4.19
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.211414
  • susdssUSDS (SUSDS) $ 1.06
  • bonkBonk (BONK) $ 0.000024
  • render-tokenRender (RENDER) $ 3.50
  • story-2Story (IP) $ 6.04
  • worldcoin-wldWorldcoin (WLD) $ 0.936395
  • official-trumpOfficial Trump (TRUMP) $ 8.64
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.87
  • binance-staked-solBinance Staked SOL (BNSOL) $ 173.39
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,081.08
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.642451
  • sei-networkSei (SEI) $ 0.287792
  • flare-networksFlare (FLR) $ 0.022805
  • skySky (SKY) $ 0.076306
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,762.34
  • filecoinFilecoin (FIL) $ 2.32
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 113,661.00
  • hash-2Provenance Blockchain (HASH) $ 0.032392
  • xdce-crowd-saleXDC Network (XDC) $ 0.093190
  • spx6900SPX6900 (SPX) $ 1.60
  • usdtbUSDtb (USDTB) $ 0.999794
  • jupiter-exchange-solanaJupiter (JUP) $ 0.462235
  • usdt0USDT0 (USDT0) $ 1.00
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,772.33
  • kucoin-sharesKuCoin (KCS) $ 10.48
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,873.67
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,842.34
  • nexoNEXO (NEXO) $ 1.29
  • injective-protocolInjective (INJ) $ 13.01
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998166
  • curve-dao-tokenCurve DAO (CRV) $ 0.894519
  • blockstackStacks (STX) $ 0.678304
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999568
  • falcon-financeFalcon USD (USDF) $ 0.999778
  • celestiaCelestia (TIA) $ 1.62
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,790.55
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 113,780.00
  • pump-funPump.fun (PUMP) $ 0.003272
  • optimismOptimism (OP) $ 0.661936
  • conflux-tokenConflux (CFX) $ 0.204545
  • saros-financeSaros (SAROS) $ 0.394301
  • wbnbWrapped BNB (WBNB) $ 750.15
  • flokiFLOKI (FLOKI) $ 0.000104
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999832
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 184.06
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.12
  • pax-goldPAX Gold (PAXG) $ 3,382.94
  • paypal-usdPayPal USD (PYUSD) $ 0.999697
  • immutable-xImmutable (IMX) $ 0.496099
  • fartcoinFartcoin (FARTCOIN) $ 0.930653
  • the-graphThe Graph (GRT) $ 0.088897
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 113,773.00
  • memecoreMemeCore (M) $ 0.547518
  • sonic-3Sonic (S) $ 0.279780
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.55
  • clbtcclBTC (CLBTC) $ 113,817.00
  • dogwifcoindogwifhat (WIF) $ 0.868470
  • ethereum-name-serviceEthereum Name Service (ENS) $ 25.75
  • msolMarinade Staked SOL (MSOL) $ 214.26
  • tether-goldTether Gold (XAUT) $ 3,381.24
  • kaiaKaia (KAIA) $ 0.140707
  • tezosTezos (XTZ) $ 0.765601
  • lido-daoLido DAO (LDO) $ 0.900185
  • vaultaVaulta (A) $ 0.500956
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.18
  • super-oethSuper OETH (SUPEROETH) $ 3,584.89
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,839.44
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,750.92
  • theta-tokenTheta Network (THETA) $ 0.746530
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,580.84
  • iotaIOTA (IOTA) $ 0.181904
  • jasmycoinJasmyCoin (JASMY) $ 0.014480
  • ousgOUSG (OUSG) $ 112.07
  • raydiumRaydium (RAY) $ 2.59
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • galaGALA (GALA) $ 0.015117
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998069
  • tbtctBTC (TBTC) $ 113,773.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,585.72
  • the-sandboxThe Sandbox (SAND) $ 0.263503
  • pyth-networkPyth Network (PYTH) $ 0.111319
  • bittorrentBitTorrent (BTT) $ 0.00000065
  • aerodrome-financeAerodrome Finance (AERO) $ 0.727039
  • pendlePendle (PENDLE) $ 3.82
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • jito-governance-tokenJito (JTO) $ 1.64
  • morphoMorpho (MORPHO) $ 1.80
  • usual-usdUsual USD (USD0) $ 0.997553
  • newton-projectAB (AB) $ 0.008098
  • zcashZcash (ZEC) $ 35.24
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 113,783.00
  • flowFlow (FLOW) $ 0.352703
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,586.79
  • stader-ethxStader ETHx (ETHX) $ 3,817.94
  • usddUSDD (USDD) $ 0.999464
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 111,278.00
  • syrupMaple Finance (SYRUP) $ 0.446170
  • walrus-2Walrus (WAL) $ 0.374939
  • decentralandDecentraland (MANA) $ 0.275625
  • beldexBeldex (BDX) $ 0.073842
  • based-brettBrett (BRETT) $ 0.051437
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.198581
  • bitcoin-svBitcoin SV (BSV) $ 25.56
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,952.41
  • heliumHelium (HNT) $ 2.69
  • vision-3Vision (VSN) $ 0.164602
  • rekt-4Rekt (REKT) $ 0.000001
  • true-usdTrueUSD (TUSD) $ 0.996083
  • swethSwell Ethereum (SWETH) $ 3,928.65
  • chain-2Onyxcoin (XCN) $ 0.013785
  • coredaoorgCore (CORE) $ 0.472146
  • telcoinTelcoin (TEL) $ 0.005108
  • apenftAPENFT (NFT) $ 0.00000048
  • build-onBUILDon (B) $ 0.469333
  • mog-coinMog Coin (MOG) $ 0.000001
  • thorchainTHORChain (RUNE) $ 1.29
  • savings-daiSavings Dai (SDAI) $ 1.16
  • zebec-networkZebec Network (ZBCN) $ 0.005161
  • apecoinApeCoin (APE) $ 0.554924
  • starknetStarknet (STRK) $ 0.115099
  • dexeDeXe (DEXE) $ 7.69
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.77
  • arweaveArweave (AR) $ 6.61
  • keetaKeeta (KTA) $ 1.06
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • reserve-rights-tokenReserve Rights (RSR) $ 0.007271
  • compound-governance-tokenCompound (COMP) $ 45.40
  • frax-etherFrax Ether (FRXETH) $ 3,577.63
  • sun-tokenSun Token (SUN) $ 0.022001
  • kavaKava (KAVA) $ 0.387174
  • tripTrip (TRIP) $ 14.18
  • neoNEO (NEO) $ 5.89
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,584.36
  • dydx-chaindYdX (DYDX) $ 0.545881
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • ether-fiEther.fi (ETHFI) $ 0.976007
  • tokenize-xchangeTokenize Xchange (TKX) $ 5.12

North Korean Hackers Are Using Fake Job Offers to Breach Cloud Systems, Steal Billions in Crypto

0 4

North Korean Hackers Are Using Fake Job Offers to Breach Cloud Systems, Steal Billions in Crypto

North Korean hacking groups are using the lure of freelance IT work to gain access to cloud systems and steal cryptocurrencies worth millions of dollars, according to separate research from Google Cloud and security firm Wiz.

Google Cloud’s H2 2025 Cloud Threat Horizons Report reveals that Google Threat Intelligence Group is “actively tracking” UNC4899, a North Korean hacking unit that successfully hacked two companies after contacting employees via social media.

In both cases, UNC4899 gave the employees tasks that resulted in the employees running malware on their workstations, enabling the hacking group to establish connections between its command-and-control centers and the target companies’ cloud-based systems.



As a result, UNC4899 was able to explore the victims’ cloud environments, obtaining credential materials and ultimately identifying hosts responsible for processing crypto transactions.

While each separate incident targeted different (unnamed) companies and different cloud services (Google Cloud and AWS), both resulted in the theft of “several millions worth of crypto.”

The use of job lures by North Korean hackers is now “quite common and widespread,” reflecting a considerable degree of sophistication, Jamie Collier, the Lead Threat Intelligence Advisor for Europe at Google Threat Intelligence Group, told Decrypt.

“They frequently pose as job recruiters, journalists, subject matter experts, or college professors when contacting targets,” he said, adding that they often communicate back and forth several times in order to build a rapport with targets.

Quick to act

Collier explains that North Korean threat actors were among the first to quickly adopt new technologies such as AI, which they use to produce “more convincing rapport-building emails” and to write their malicious scripts.

Also reporting on UNC4899’s exploits is cloud security firm Wiz, which notes that the group is also referred to by the names TraderTraitor, Jade Sleet, and Slow Pisces.

TraderTraitor represents a certain kind of threat activity rather than a specific group, with the North Korea-backed entities Lazarus Group, APT38, BlueNoroff, and Stardust Chollima all behind typical TraderTraitor exploits, Wiz said.

In its analysis of UNC4899/TraderTraitor, Wiz notes that campaigns began back in 2020 and that from the beginning, the responsible hacking groups used job lures to coax employees into downloading malicious crypto apps that were built on JavaScript and Node.js using the Electron framework.

The group’s campaign from 2020 to 2022 “successfully breached multiple organizations,” according to Wiz, including Lazarus Group’s $620 million breach of Axie Infinity’s Ronin Network.

TraderTraitor threat activity then evolved in 2023 to incorporate the use of malicious open-source code, while in 2024, it doubled down on fake job offers, primarily targeting exchanges.

Most notably, TraderTraitor groups were responsible for the $305 million hack of Japan’s DMM Bitcoin, and also the $1.5 billion Bybit hack in late 2024, which the exchange revealed in February of this year.

Targeting the cloud

As with the exploits highlighted by Google, these hacks targeted cloud systems to varying degrees, and according to Wiz, such systems represent a significant vulnerability for crypto.

“We believe that TraderTraitor has focused on cloud-related exploits and techniques because that is where the data, and thus money, is,” Benjamin Read, Wiz’s Director of Strategic Threat Intelligence, told Decrypt. “This is especially true for the crypto industry, where the companies are newer and likely to have built their infrastructure in a cloud-first manner.”

Read explained that targeting cloud technologies enables hacking groups to impact a wide range of targets, increasing the potential to make more money.

These groups are doing big business, with “estimates of $1.6 billion in cryptocurrency stolen so far in 2025,” he said, adding that TraderTraitor and related groups have workforces “likely in the thousands of people,” who work in numerous and sometimes overlapping groups. 

“While coming up with a specific number is difficult, it is clear that the North Korean regime is investing significant resources in these capabilities.”

Ultimately, such investment has enabled North Korea to become a leader in crypto hacking, with a February TRM Labs report concluding that the country accounted for 35% of all stolen funds last year.

Experts said all available signs suggest the country is likely to remain a fixture in crypto-related hacking for some time to come, especially given the ability of its operatives to develop new techniques.

“​​North Korean threat actors are a dynamic and agile force that continuously adapts to meet the regime’s strategic and financial objectives,” Google’s Collier said.

Reiterating that North Korean hackers are increasingly making use of AI, Collier explained that such use enables “force multiplication,” which in turn has enabled the hackers to scale up their exploits. 

“We see no evidence of them slowing down and anticipate this expansion to continue,” he said.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights