North Korea Stole $659 Million in Crypto Assets Last Year: US Report
Joint Advisory Highlights North Korean Cyber Threat
The United States, Japan, and South Korea have jointly issued a warning regarding the aggressive actions of North Korean cyber criminals targeting the cryptocurrency industry. The advisory reveals that groups affiliated with the Democratic People's Republic of Korea (DPRK), including the notorious Lazarus hacking group, have been conducting widespread cyber-attacks. These attacks are primarily aimed at various targets such as exchanges, digital asset custodians, and individual users, resulting in the theft of $659 million worth of crypto assets in 2024 alone.
Social Engineering Tactics Unveiled
The joint advisory explains how North Korean hackers employ sophisticated social engineering tactics to penetrate systems. Threat actors often impersonate freelance IT workers to gain access, exploiting vulnerabilities by using well-crafted disguises. The advisory further warns about the potential infiltration into private sector systems, where hackers may pose as legitimate IT freelancers. Identified tactics include logging in from multiple IP addresses, transferring funds to China-based accounts, requesting cryptocurrency payments, inconsistent background information, and inaccessibility during typical business hours.
Malware Deployment and Currency Theft
Once these hackers infiltrate a system, they typically deploy malware such as keyloggers and remote access tools, facilitating the theft of login credentials and virtual currencies. The stolen cryptocurrencies are then controlled and liquidated by the hackers.
Funding Unlawful Military Programs
According to a 2022 UN report, the funds acquired through these cyber thefts are believed to be funnelled into North Korea's missile programs. "Our three governments strive together to prevent thefts, including from private industry, by the DPRK and to recover stolen funds with the ultimate goal of denying the DPRK illicit revenue for its unlawful weapons of mass destruction and ballistic missile programs," stated the governments of the US, Japan, and South Korea.