Skip to content
← Back to newsNorth Korean Hackers Exploit Crypto Industry With Fake U.S. Companies
Security

North Korean Hackers Exploit Crypto Industry With Fake U.S. Companies

By ToTo BugelmanNewcomer0 rep· 4/26/2025

North Korean hackers have escalated their cyber operations by establishing fake U.S.-based companies to target cryptocurrency developers. This sophisticated scheme, linked to the notorious Lazarus Group, involves using deceptive job offers to distribute malware, posing a significant threat to the crypto sector.

 

Zach Edwards

 

Key Takeaways

  • North Korean hackers created three fake companies to lure crypto developers.

  • The scheme involves fake job interviews leading to malware downloads.

  • The FBI has intervened by seizing one of the domains used in the attacks.

 

The Scheme Unveiled

According to cybersecurity experts, the Lazarus Group has registered three fraudulent companies: Blocknovas LLC, Softglide LLC, and Angeloper Agency. These companies were designed to appear legitimate, complete with fabricated identities and addresses in the U.S.

  • Blocknovas LLC: Registered in New Mexico, it used a non-existent address.

  • Softglide LLC: Registered in New York, linked to a tax office.

  • Angeloper Agency: Another front company involved in the scheme.

The hackers employed social engineering tactics, including fake job postings and interviews, to engage unsuspecting developers. During these interactions, victims were prompted to download files disguised as application materials, which contained malware.

 

During the sham job interview, an error message is displayed, requiring the user to click, copy, and paste to fix it, which leads to the malware infection: Zach Edwards

 

Malware Delivery Tactics

The malware used in this campaign includes three distinct strains: BeaverTail, InvisibleFerret, and OtterCookie. These malicious tools allow hackers to:

  • Steal sensitive data, including passwords and private keys for cryptocurrency wallets.

  • Gain backdoor access to victims' systems, enabling further attacks.

The process typically involves a fake job application where candidates are asked to upload an introductory video. When they encounter an error, they are provided with a misleading solution that leads to malware installation.

 

Advanced Techniques and AI Usage

In a concerning twist, the hackers have also utilized artificial intelligence to create fake employee profiles. This includes:

  • Generating images of non-existent employees using AI tools.

  • Altering real images of individuals to create deceptive profiles.

This level of sophistication marks a significant evolution in cybercrime tactics, making it increasingly difficult for victims to identify fraudulent activities.

 

FBI's Response

The FBI has taken action against this cyber threat by seizing the domain associated with Blocknovas LLC. This intervention is part of a broader effort to combat North Korean cyber operations, which are considered one of the most persistent threats to U.S. cybersecurity.

  • The FBI's actions highlight the ongoing risks posed by North Korean hackers, who have previously stolen billions in digital assets to fund their government and military activities.

  • The operation violates U.S. and United Nations sanctions, which prohibit North Korea from engaging in commercial activities that support its regime.

 

Conclusion

This incident serves as a stark reminder for cryptocurrency developers to remain vigilant against increasingly sophisticated cyber threats. As North Korean hackers continue to refine their tactics, the need for robust cybersecurity measures in the crypto industry has never been more critical. Developers are urged to exercise caution when engaging with potential employers and to be aware of the signs of phishing and malware distribution.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

North Korean Hackers Exploit Crypto Industry With Fake U.S. Companies | BlockzHub