North Korean hackers employ new tactics: Pay $500 to get hired, then impersonate employees

icon MarsBit
Share
AI summary iconSummary
North Korean hackers are employing new methods to infiltrate crypto firms, paying $500 monthly in cryptocurrency to third parties to pass job interviews. Once hired, they impersonate employees to gain access to sensitive data and assets. A report by the U.S., FBI, and 11 other nations revealed how they use fake IDs, AI, and remote work tools. Companies are urged to watch for red flags such as unusual IP activity and irregular work patterns. Traders are advised to monitor altcoins amid rising volatility in the Fear & Greed Index.

Original | Odaily Planet Daily (@OdailyChina)

Author | Wenser (@wenser 2010)

DeFi

Do you remember the North Korean hacker who gained access to the MetaMask wallet through a third-party contractor? (Recommended reading: “Close Call! A Contractor Almost Destroyed MetaMask”)

What about the North Korean hacker exposed by a fake DeFi company’s sting operation? (Recommended reading: “The Annual Phishing Drama: Fake DeFi Unmasks the Real North Korean Lazarus Hackers”)

Like security firms engaged in proactive sting operations, North Korean hackers are escalating their tactics—from initially exploiting technical vulnerabilities, to later using social engineering, and then outsourcing projects to gain entry into crypto initiatives. Recently, their infiltration methods have taken a new turn: they first hire individuals to pass interviews at crypto companies, then replace them internally to gain employment, lie in wait, and eventually launch insider technical attacks to steal crypto assets and sensitive information.

A month later, the conflict between the security firm and North Korean hackers has taken a new turn, and a new type of scam has emerged.

“Indirect approach”: The hacker hired someone for an interview, took over the position, and ultimately did it all to “serve the motherland”

First, let’s look at the “track record” of North Korean hackers: According to data from cybersecurity firm CrowdStrike, North Korean state-linked hackers and threat actors caused over $2 billion in cryptocurrency losses in 2025, a 51% year-over-year increase; the Bank of Korea estimates that despite global sanctions, North Korea’s GDP growth rate in 2025 remained as high as 3.5%.

The confirmed information is that North Korean hackers, as a "national team," have also contributed significantly to its economic growth.

On July 31 of this year, the U.S. Department of State and the FBI, in collaboration with 11 countries including Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom, issued a security alert titled "Alert on North Korean IT Workers".

The report contains a significant amount of information, including the following key points:

First, North Korea relies on a network of technical developers deployed domestically and abroad to conduct external operations, sending these technicians to obtain false identities and earn income through remote work, ultimately transferring their salaries to accounts controlled by North Korean government agencies. These funds are ultimately used to develop and advance North Korea’s nuclear weapons and ballistic missile programs.

Second, based on the specific job responsibilities of North Korean hackers, these technical developers typically obtain employment and corresponding salary income through online employment, procurement, and contracting platforms operated by private companies abroad, using forged identities of citizens from other countries.

Again, beyond this, North Korean technical staff not only earn standard employee salaries but also pose a significant internal threat to the commercial information and assets of the companies they join. A substantial number have taken advantage of this opportunity to engage in data theft, cryptocurrency theft, and the theft of sensitive information.

Finally, from the perspective of specific implementation methods, North Korean hackers' preparatory activities and operational techniques are becoming increasingly sophisticated, even including the use of AI models and tools to create fake identities and carry out illegal activities worldwide.

Notably, the most important point mentioned in this report is that, building on previous "in-person interviews," North Korean hackers have recently upgraded their "workflow"—

  • Currently, they often recruit technical staff from third countries (such as Iran, Lebanon, etc.) in advance through recruitment websites like LinkedIn;
  • Subsequently, North Korean hackers will ask certain technical developers to work part-time as “interview assistants,” offering them a monthly cryptocurrency payment of $500 to help them gain employment at target companies.
  • Finally, North Korean hackers replace themselves and join the target company as members of the team, enabling technical infiltration while earning salaries for their positions, all while secretly stealing sensitive information, data, cryptocurrency assets, and technical code as corporate assets.

Undoubtedly, in the ongoing escalation of security battles, North Korean hackers are also upgrading their own "SOPs (standard operating procedures)," with their ultimate goal being to repatriate funds to their home country.

North Korean hacker infiltration self-assessment checklist: From employee personal information to daily expression habits

Currently, North Korean hackers’ tactics are difficult to defend against, but they still follow discernible patterns. Below are some indicators that companies should be vigilant about and self-check:

Companies operating online platforms need to pay special attention to the following aspects:

  • Employees frequently change their registration information (username, contact details, payment bank accounts, etc.).
  • The name on the employee's ID document does not match the name on the registered payment account.
  • Create multiple receiving accounts using the same identity document.
  • The identity verification document appears to be forged or generated/altered using image editing software or AI image generation tools.
  • Multiple technical accounts are making access requests from the same IP address.
  • A single account is making access requests from multiple IP addresses in a short period of time.
  • The account has been logged in for an unusually long time.
  • Unusual cumulative working hours or related work metrics (e.g., excessively long online time, unusually high productivity, or excessive workload).
  • Users of job search websites create fake reviews to boost the platform's rating, among other things.

For companies hiring employees or conducting interviews and engaging contractors, paying attention to the following details can help prevent internal infiltration by North Korean hackers:

  • The candidate's profile contains errors or unnatural phrasing (likely machine-translated), claiming limited proficiency in their native language (given the prevalence of AI translation services, greater attention should be paid to their language expression).
  • In video conferences, forged details are exposed, such as photos not matching identity information; the video feed is AI-generated or coordinated by a third party, with unnatural speech patterns and body language.
  • An interviewee refused to participate in the video call and declined to turn on their camera.
  • The labor compensation quote is below the general market price.
  • It shows that the personal technical account is operated by multiple people (typically indicating that such hacking activities are often carried out by teams, with the actual interacting parties potentially changing over time).
  • Require payment in cryptocurrency and do not provide complete bank account or payment account information.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.