North Korea stole $659 million in crypto assets last year, the US says

The United States, Japan and South Korea have issued a warning against North Korean threat actors, who are actively and aggressively targeting the cryptocurrency industry. In their joint advisory, the countries said threat actor groups affiliated with the Democratic People's Republic of Korea (DPRK) continue to stage numerous cybercrime campaigns to steal cryptocurrency. Those bad actors — including the Lazarus hacking group, which the US believes has been deploying cyber attacks all over the world since 2009 — target "exchanges, digital asset custodians and individual users." And apparently, they stole $659 million in crypto assets in 2024 alone. 

North Korean hackers have been using "well-disguised social engineering attacks" to infiltrate their targets' systems, the countries said. They also warned that the actors could get access to systems owned by the private sector by posing as freelance IT workers. Back in 2022, the US issued guidelines on how to identify potential workers from North Korea, such as how they'd typically log in from multiple IP addresses, transfer money to accounts based in the People's Republic of China, ask for crypto payments, have inconsistencies with their background information and be unreachable at times during their supposed business hours. 

Once the bad actors are in, they then usually deploy malware, such as keyloggers and remote access tools, to be able to steal login credentials and, ultimately, virtual currency they can control and sell. As for where the stolen funds go: The UN issued a report in 2022, revealing its investigators' discovery that North Korea uses money stolen by affiliated threat actors for its missile programs. "Our three governments strive together to prevent thefts, including from private industry, by the DPRK and to recover stolen funds with the ultimate goal of denying the DPRK illicit revenue for its unlawful weapons of mass destruction and ballistic missile programs," the US, Japan and South Korea said.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/north-korea-stole-659-million-in-crypto-assets-last-year-the-us-says-133029741.html?src=rss https://www.engadget.com/cybersecurity/north-korea-stole-659-million-in-crypto-assets-last-year-the-us-says-133029741.html?src=rss
Utworzony 1mo | 15 sty 2025, 13:50:14


Zaloguj się, aby dodać komentarz

Inne posty w tej grupie

The secretive X-37B space plane snapped this picture of Earth from orbit

It’s not every day that we get to see a glimpse of what a mysterious space plane is up to in orbit. This week, the US Space Force shared a picture it says was snapped last year by the X-37B, showin

22 lut 2025, 22:30:11 | Engadget
An XR game trilogy based on Neon Genesis Evangelion is in the works

South Korean game development studio Pixelity says it’s working on a series of XR games based on Neon Genesis Evangelion, and the first one will be released next year. In an emailed announ

22 lut 2025, 22:30:10 | Engadget
The creator of My Friend Pedro has a new game on the way, and it looks amazingly weird

There’s a lot to take in in the announcement trailer for Shotgun Cop Man: the wide-bodied

22 lut 2025, 20:10:22 | Engadget
What we’re listening to: Bad Bunny, The Weeknd, FKA twigs and more

In What We’re Listening To, Engadget editors and writers discuss the new music we can’t get enough of.

22 lut 2025, 17:40:19 | Engadget
Meta approves massive bonuses for executives after broad layoffs

Meta has offered up a lucrative new executive bonus plan, accord

22 lut 2025, 10:50:07 | Engadget
Bybit hacked for almost $1.5 billion in the biggest crypto theft ever

While 20th-century heists involved scoping out a location, recruiting a person on the inside and having a daredevil getaway driver waiting outside, the 21st-century version looks more like what Byb

21 lut 2025, 23:20:09 | Engadget