Japanese and U.S. authorities, including the FBI, confirmed the group targets web designers and blockchain engineers by posing as legitimate AI or NFT companies. Attackers utilize malicious coding tests and interview assignments to deploy a suite of information-stealing software, such as BeaverTail and InvisibleFerret. These tools grant the group persistent access, allowing them to harvest browser credentials, identity documents, and private keys from infected machines.
Beyond direct cyberattacks, the investigation uncovered an extensive network of “laptop farms” used to facilitate illicit employment. By using stolen identities and remote access tools, North Korean IT workers secure jobs at Western and Japanese firms, funneling their earnings—which have reached at least 1.7 billion yen—back to state-controlled coffers. In one instance, a suspected operative attempted to infiltrate the exchange bitFlyer in 2025, providing fake credentials and insisting on cryptocurrency payments before being flagged by security protocols.

Comments (0)
No comments yet. Be the first!