pwshub.com

North Korea Deploying ‘Highly Tailored, Difficult-To-Detect’ Tactics To Steal Crypto From Businesses: FBI

North Korea has been running highly sophisticated social engineering schemes designed to crack the security measures of crypto and decentralized finance (DeFi) firms, according to the U.S. Federal Bureau of Investigation (FBI).

A new FBI public service announcement indicates North Korean cyber criminals target specific employees at firms connected to crypto exchange-traded funds (ETFs).

“Before initiating contact, the actors scout prospective victims by reviewing social media activity, particularly on professional networking or employment-related platforms.

North Korean malicious cyber actors incorporate personal details regarding an intended victim’s background, skills, employment, or business interests to craft customized fictional scenarios designed to be uniquely appealing to the targeted person.”

The FBI says fake scenarios often include new job opportunities or promises of corporate investment. North Korean cyber criminals can speak fluent English, demonstrate crypto technical prowess and will often reference obscure, highly targeted personal information designed to feign legitimacy, according to the law enforcement agency.

“The actors usually attempt to initiate prolonged conversations with prospective victims to build rapport and deliver malware in situations that may appear natural and non-alerting.”

The FBI says red flags include:

  • “Requests to execute code or download applications on company-owned devices or other devices with access to a company’s internal network.
  • Requests to conduct a ‘pre-employment test’ or debugging exercise that involves executing non-standard or unknown Node.js packages, PyPI packages, scripts, or GitHub repositories.
  • Offers of employment from prominent cryptocurrency or technology firms that are unexpected or involve unrealistically high compensation without negotiation.
  • Offers of investment from prominent companies or individuals that are unsolicited or have not been proposed or discussed previously.
  • Insistence on using non-standard or custom software to complete simple tasks easily achievable through the use of common applications (i.e. video conferencing or connecting to a server).
  • Requests to run a script to enable call or video teleconference functionalities supposedly blocked due to a victim’s location.
  • Requests to move professional conversations to other messaging platforms or applications.
  • Unsolicited contacts that contain unexpected links or attachments.”

The FBI recommends that crypto firm employees verify the identities of their contacts through other communication platforms and avoid taking pre-employment tests for potential new jobs on existing work laptops.

The agency also suggests firms keep information about crypto wallets offline; install multiple factors of authentication to move corporate financial assets; limit access to sensitive network documentation; funnel business communications to closed platforms that require in-person authentication; and disable email attachments by default on company devices.

Generated Image: Midjourney

Source: dailyhodl.com

Related stories
2 weeks ago - The FBI has issued an alert warning that North Korean hackers are attempting to steal cryptocurrency funds from U.S.-based ETFs using sophisticated social engineering techniques.
1 day ago - Decentralized Finance (DeFi) platform Delta Primes suffered a security breach on Monday, affecting the protocol’s users. The attack took $6 million from the project’s pools and is under investigation. However, on-chain investigators...
1 month ago - Chainalysis found some attackers, including those linked to North Korea, have even gone as far as applying for IT jobs at targeted companies.
3 days ago - Circle's delayed response to blacklisting funds highlights the urgent need for stricter regulatory oversight and faster incident response in the crypto industry. The post Circle accused of ‘extracting’ from Lazarus Group hacks, faces...
2 weeks ago - The WazirX hacker has carried out 26 transactions, each transferring 100 ETH to Tornado Cash, according to Arkham Intelligence.
Other stories
16 minutes ago - Donald Trump used Bitcoin to pay for burgers at PubKey bar in New York City, all while rallying BTC fans to vote.
26 minutes ago - First Neiro on Ethereum (NEIRO), a meme coin, is one of the top performers this week. Over the last seven days alone, the token has soared over 332X, pushing its total market cap over the $341 million mark–a testament to a token that...
1 hour ago - The makers of Parallel are expanding the Ethereum card battler's universe with Project Tau Ceti, a 3D shooter on Base gaming network B3.
1 hour ago - Recent Ethereum price action saw ETH reaching another low of $2,150 on September 6, raising concerns of a more severe drop towards the $2,000 price level. Although these concerns were eased with a subsequent bounce to $2,460 on September...
1 hour ago - A crypto strategist known for making timely altcoin calls believes layer-1 protocol Sui (SUI) is gearing up to spark breakout rallies. Pseudonymous analyst Bluntz tells his 274,600 followers on the social media platform X that SUI appears...