• bitcoinBitcoin (BTC) $ 107,980.00
  • ethereumEthereum (ETH) $ 3,777.15
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,083.39
  • xrpXRP (XRP) $ 2.47
  • usd-coinUSDC (USDC) $ 0.999785
  • staked-etherLido Staked Ether (STETH) $ 3,775.01
  • dogecoinDogecoin (DOGE) $ 0.181993
  • tronTRON (TRX) $ 0.290980
  • cardanoCardano (ADA) $ 0.610097
  • wrapped-stethWrapped stETH (WSTETH) $ 4,598.72
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 107,852.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,078.16
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.999050
  • hyperliquidHyperliquid (HYPE) $ 46.98
  • chainlinkChainlink (LINK) $ 17.01
  • bitcoin-cashBitcoin Cash (BCH) $ 538.56
  • wrapped-eethWrapped eETH (WEETH) $ 4,078.81
  • stellarStellar (XLM) $ 0.299341
  • ethena-usdeEthena USDe (USDE) $ 0.999109
  • usdsUSDS (USDS) $ 0.999930
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.61
  • suiSui (SUI) $ 2.32
  • wethWETH (WETH) $ 3,776.88
  • hedera-hashgraphHedera (HBAR) $ 0.193888
  • avalanche-2Avalanche (AVAX) $ 18.42
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,956.00
  • litecoinLitecoin (LTC) $ 92.84
  • usdt0USDT0 (USDT0) $ 0.999450
  • moneroMonero (XMR) $ 321.13
  • whitebitWhiteBIT Coin (WBT) $ 41.09
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • zcashZcash (ZEC) $ 332.41
  • the-open-networkToncoin (TON) $ 2.15
  • crypto-com-chainCronos (CRO) $ 0.141822
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • mantleMantle (MNT) $ 1.50
  • daiDai (DAI) $ 1.00
  • memecoreMemeCore (M) $ 2.62
  • polkadotPolkadot (DOT) $ 2.88
  • bittensorBittensor (TAO) $ 413.90
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.139055
  • uniswapUniswap (UNI) $ 5.87
  • susdssUSDS (SUSDS) $ 1.08
  • aaveAave (AAVE) $ 214.96
  • okbOKB (OKB) $ 151.99
  • bitget-tokenBitget Token (BGB) $ 4.54
  • usd1-wlfiUSD1 (USD1) $ 0.999761
  • ethenaEthena (ENA) $ 0.408546
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999850
  • pepePepe (PEPE) $ 0.000007
  • nearNEAR Protocol (NEAR) $ 2.13
  • jito-staked-solJito Staked SOL (JITOSOL) $ 231.22
  • solanaSolana (SOL) $ 186.45
  • ethereum-classicEthereum Classic (ETC) $ 15.31
  • aptosAptos (APT) $ 3.21
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,776.15
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.40
  • ondo-financeOndo (ONDO) $ 0.690619
  • falcon-financeFalcon USD (USDF) $ 0.997353
  • tether-goldTether Gold (XAUT) $ 3,996.70
  • pi-networkPi Network (PI) $ 0.246341
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.186596
  • usdtbUSDtb (USDTB) $ 0.999348
  • aster-2Aster (ASTER) $ 0.906531
  • worldcoin-wldWorldcoin (WLD) $ 0.800137
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 13.00
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,332.56
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 47.11
  • binance-staked-solBinance Staked SOL (BNSOL) $ 201.29
  • pump-funPump.fun (PUMP) $ 0.004626
  • arbitrumArbitrum (ARB) $ 0.296637
  • official-trumpOfficial Trump (TRUMP) $ 8.06
  • gatechain-tokenGate (GT) $ 13.34
  • internet-computerInternet Computer (ICP) $ 2.90
  • algorandAlgorand (ALGO) $ 0.175026
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,992.42
  • story-2Story (IP) $ 4.44
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,984.43
  • kaspaKaspa (KAS) $ 0.052926
  • cosmosCosmos Hub (ATOM) $ 2.97
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,073.20
  • vechainVeChain (VET) $ 0.015755
  • wbnbWrapped BNB (WBNB) $ 1,083.30
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 3,993.47
  • hash-2Provenance Blockchain (HASH) $ 0.026285
  • skySky (SKY) $ 0.056708
  • bfusdBFUSD (BFUSD) $ 0.999832
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 108,054.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.394008
  • flare-networksFlare (FLR) $ 0.016164
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.019212
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,012.60
  • sei-networkSei (SEI) $ 0.187005
  • render-tokenRender (RENDER) $ 2.25
  • quant-networkQuant (QNT) $ 79.35
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • nexoNEXO (NEXO) $ 1.11
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 107,771.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.059117
  • bonkBonk (BONK) $ 0.000014
  • filecoinFilecoin (FIL) $ 1.48
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997848
  • morphoMorpho (MORPHO) $ 1.92
  • global-dollarGlobal Dollar (USDG) $ 0.999893
  • immutable-xImmutable (IMX) $ 0.486859
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,065.88
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 214.19
  • ripple-usdRipple USD (RLUSD) $ 0.999559
  • aerodrome-financeAerodrome Finance (AERO) $ 1.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.36
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 107,898.00
  • clbtcclBTC (CLBTC) $ 111,678.00
  • spx6900SPX6900 (SPX) $ 0.921666
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.41
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • ousgOUSG (OUSG) $ 113.11
  • celestiaCelestia (TIA) $ 0.932851
  • optimismOptimism (OP) $ 0.408350
  • msolMarinade Staked SOL (MSOL) $ 248.78
  • injective-protocolInjective (INJ) $ 7.89
  • fasttokenFasttoken (FTN) $ 1.78
  • lido-daoLido DAO (LDO) $ 0.850538
  • blockstackStacks (STX) $ 0.414075
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.87
  • curve-dao-tokenCurve DAO (CRV) $ 0.505267
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998002
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • doublezeroDoubleZero (2Z) $ 0.195998
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,776.55
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 4,009.75
  • flokiFLOKI (FLOKI) $ 0.000067
  • tbtctBTC (TBTC) $ 107,550.00
  • the-graphThe Graph (GRT) $ 0.060535
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.243554
  • beldexBeldex (BDX) $ 0.080895
  • tezosTezos (XTZ) $ 0.566068
  • pyth-networkPyth Network (PYTH) $ 0.104236
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,776.84
  • kaiaKaia (KAIA) $ 0.101683
  • usdaiUSDai (USDAI) $ 1.01
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999821
  • stader-ethxStader ETHx (ETHX) $ 4,052.59
  • gtethGTETH (GTETH) $ 3,767.68
  • plasmaPlasma (XPL) $ 0.304473
  • sonic-3Sonic (S) $ 0.148123
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999640
  • iotaIOTA (IOTA) $ 0.134548
  • dashDash (DASH) $ 43.88
  • usual-usdUsual USD (USD0) $ 0.998049
  • newton-projectAB (AB) $ 0.006361
  • conflux-tokenConflux (CFX) $ 0.102384
  • pendlePendle (PENDLE) $ 3.07
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,156.66
  • humanityHumanity (H) $ 0.282341
  • wrapped-hypeWrapped HYPE (WHYPE) $ 46.87
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.22
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.993972
  • swethSwell Ethereum (SWETH) $ 4,161.69
  • ether-fiEther.fi (ETHFI) $ 0.890790
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 108,122.00
  • dogwifcoindogwifhat (WIF) $ 0.496201
  • true-usdTrueUSD (TUSD) $ 0.998027
  • theta-tokenTheta Network (THETA) $ 0.486377
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.64
  • the-sandboxThe Sandbox (SAND) $ 0.197586
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • jasmycoinJasmyCoin (JASMY) $ 0.009826
  • bittorrentBitTorrent (BTT) $ 0.00000048
  • starknetStarknet (STRK) $ 0.108553
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,144.46
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.181913
  • syrupMaple Finance (SYRUP) $ 0.415755
  • galaGALA (GALA) $ 0.009982
  • chainopera-aiChainOpera AI (COAI) $ 2.36
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,774.59
  • raydiumRaydium (RAY) $ 1.65
  • usddUSDD (USDD) $ 0.999810
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,075.92
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 47.43
  • myx-financeMYX Finance (MYX) $ 2.25
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 22.71
  • ghoGHO (GHO) $ 0.999436
  • heliumHelium (HNT) $ 2.28
  • sun-tokenSun Token (SUN) $ 0.022231
  • bitcoin-svBitcoin SV (BSV) $ 21.34
  • vaultaVaulta (A) $ 0.265918
  • decentralandDecentraland (MANA) $ 0.221134
  • flowFlow (FLOW) $ 0.260277
  • swissborgSwissBorg (BORG) $ 0.424157
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,781.07
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,066.27
  • usdbUSDB (USDB) $ 0.988215
  • apenftAINFT (NFT) $ 0.00000041
  • satoshi-stablecoinSatoshi Stablecoin (SATUSD) $ 0.994214

North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets

0 87

North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets

North Korea’s Lazarus Group, through its subunit, spun up fake US-registered companies as part of a campaign to phish crypto developers and steal their wallets, according to a new report from Reuters.

The companies, Blocknovas LLC and Softglide LLC, were registered in New Mexico and New York using fake personas and addresses. Another entity, Angeloper Agency, is reportedly connected to the operation, but it is not registered in the US.

The scheme

The tactics involved creating fake companies, establishing a convincing online presence, and posting job listings targeting developers.

Hackers used false identities, made-up addresses, and real platforms like LinkedIn and Upwork to appear legitimate and attract developers. Once applicants opted in, they were taken through fake interviews and instructed to download test assignments or software.

These files contained malware that, once executed, gave attackers access to the victim’s system, allowing them to extract passwords, crypto wallet keys, and other sensitive data.

Russian-speaking group used nearly identical tactics in earlier campaign

In February, BleepingComputer reported that Crazy Evil, a Russian-speaking cybercrime group, had already deployed comparable tactics in a targeted scam against crypto and web3 job seekers.

A subgroup of Crazy Evil created a fake company called ChainSeeker.io, posting fraudulent listings on platforms like LinkedIn. Applicants were directed to download a malicious app, GrassCall, which installed malware designed to steal credentials, crypto wallets, and sensitive files.

The operation was well-coordinated, using cloned websites, fake profiles, and Telegram to distribute malware.

FBI confirms North Korean link

Kasey Best, director of threat intelligence at Silent Push, said this is one of the first known cases of North Korean hackers setting up legally registered companies in the US to bypass scrutiny and gain credibility.

Silent Push traced the hackers back to the Lazarus Group and confirmed multiple victims of the campaign, identifying Blocknovas as the most active of the three front companies they uncovered.

The FBI seized Blocknovas’ domain as part of enforcement actions against North Korean cyber actors who used fake job postings to distribute malware.

North Korea’s Lazarus Group sets up fictitious US companies to farm dev wallets

FBI officials said they continue to “focus on imposing risks and consequences, not only on the DPRK actors themselves, but anybody who is facilitating their ability to conduct these schemes.”

According to an FBI official, North Korean cyber operations are among the nation’s most sophisticated persistent threats.

North Korea leverages Russian infrastructure to scale attacks

To overcome limited domestic internet access, North Korea’s hacking group uses international infrastructure, particularly Russian IP ranges hosted in Khasan and Khabarovsk, towns with direct ties to North Korea, according to an in-depth analysis from Trend Micro.

Using VPNs, RDP sessions, and proxy services like Astrill VPN and CCProxy, Lazarus operatives are able to manage attacks, communicate via GitHub and Slack, and access platforms such as Upwork and Telegram.

Researchers at Silent Push have identified seven instructional videos recorded by accounts linked to BlockNovas as part of the operation. The videos describe how to set up command-and-control servers, steal passwords from browsers, upload stolen data to Dropbox, and crack crypto wallets with tools such as Hashtopolis.

From theft to state-sponsored espionage

Hundreds of developers have been targeted, with many unknowingly exposing their sensitive credentials. Some breaches appear to have escalated beyond theft, suggesting Lazarus may have handed over access to other state-aligned teams for espionage purposes.

US, South Korean, and UN officials have confirmed to Reuters that North Korea’s hackers have deployed thousands of IT workers overseas to generate millions in funding for Pyongyang’s nuclear missile program.

Source

Leave A Reply

Your email address will not be published.