Inside North Korean IT Workers’ Secret Crypto Operations Inside North Korean IT Workers’ Secret Crypto Operations

Inside North Korean IT Workers’ Secret Crypto Operations

Investigations by popular blockchain sleuth ZachXBT have uncovered extensive North Korean infiltration in the global cryptocurrency development job market.

An unnamed source recently compromised a device belonging to a DPRK IT worker and provided unprecedented insight into how a small team of five IT workers operated over 30 fake identities.

DPRK Operatives Flood Crypto Job Market

According to ZachXBT’s tweets, the DPRK team reportedly used government-issued IDs to register accounts on Upwork and LinkedIn, to obtain developer roles on multiple projects. Investigators found an export of the workers’ Google Drive, Chrome profiles, and screenshots, which revealed that Google products were central to organizing schedules, tasks, and budgets, with communications primarily conducted in English.

Among the documents is a 2025 spreadsheet containing weekly reports from team members, which shed light on their internal operations and mindset. Typical entries included statements such as “I can’t understand the job requirement, and don’t know what I need to do,” with self-directed notes like “Solution / fix: Put enough efforts in heart.”

Another spreadsheet tracks expenses, showing purchases of Social Security numbers, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, computer rentals, and VPN or proxy services. Meeting schedules and scripts for fake identities, including one under the name “Henry Zhang,” were also recovered.

The team’s operational methods reportedly involved purchasing or renting computers, using AnyDesk to perform work remotely, and converting earned fiat into cryptocurrency via Payoneer. One wallet address, 0x78e1, associated with the group is linked on-chain to a $680,000 exploit at Favrr in June 2025, where the project’s CTO and other developers were later identified as DPRK IT workers using fraudulent documents. Additional DPRK-linked workers were connected to projects via the 0x78e1 address.

Indicators of their North Korean origin include frequent use of Google Translate for Korean-language searches conducted from Russian IP addresses. ZachXBT said that these IT workers are not particularly sophisticated, but their persistence is bolstered by the sheer number of roles they target across the world.

Challenges in countering these operations include poor collaboration between private companies and services, as well as resistance from teams when fraudulent activity is reported.

North Korea’s Persistent Threat

North Korean hackers, notably the Lazarus Group, continue to pose a significant threat to the industry. In February 2025, the group orchestrated the largest crypto exchange hack in history, as it stole approximately $1.5 billion in Ethereum from Dubai-based Bybit.

The attack exploited vulnerabilities in a third-party wallet provider, Safe{Wallet}, which allowed the hackers to bypass multi-signature security measures and siphon funds into multiple wallets. The FBI attributed the breach to North Korean operatives, labeling it “TraderTraitor”.

Subsequently, in July 2025, CoinDCX, an Indian cryptocurrency exchange, fell victim to a $44 million heist, which was also linked to the Lazarus Group. The attackers infiltrated CoinDCX’s liquidity infrastructure, exploiting exposed internal credentials to execute the theft.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Chayanika Deka

https://cryptopotato.com/google-docs-upwork-and-linkedin-inside-north-korean-it-workers-secret-crypto-operations/

2025-08-17 03:31:00

bitcoin
Bitcoin (BTC) $ 118,729.00 2.19%
ethereum
Ethereum (ETH) $ 4,104.13 5.06%
tether
Tether (USDT) $ 1.00 0.00%
bnb
BNB (BNB) $ 1,223.59 0.97%
xrp
XRP (XRP) $ 2.74 2.39%
solana
Solana (SOL) $ 211.16 3.55%
usd-coin
USDC (USDC) $ 0.999786 0.00%
dogecoin
Dogecoin (DOGE) $ 0.237171 3.08%
staked-ether
Lido Staked Ether (STETH) $ 4,101.49 4.63%
tron
TRON (TRX) $ 0.331157 1.32%
cardano
Cardano (ADA) $ 0.783321 2.60%
wrapped-steth
Wrapped stETH (WSTETH) $ 4,989.03 4.67%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 118,646.00 1.94%
ethena-usde
Ethena USDe (USDE) $ 0.998326 0.09%
chainlink
Chainlink (LINK) $ 21.34 0.77%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 4,425.06 4.52%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.46%
sui
Sui (SUI) $ 3.31 1.79%
stellar
Stellar (XLM) $ 0.369115 1.51%
hyperliquid
Hyperliquid (HYPE) $ 42.68 0.96%
bitcoin-cash
Bitcoin Cash (BCH) $ 577.00 0.07%
avalanche-2
Avalanche (AVAX) $ 26.93 3.85%
wrapped-eeth
Wrapped eETH (WEETH) $ 4,422.80 4.78%
litecoin
Litecoin (LTC) $ 128.23 8.51%
weth
WETH (WETH) $ 4,101.05 4.76%
leo-token
LEO Token (LEO) $ 9.58 0.76%
hedera-hashgraph
Hedera (HBAR) $ 0.206697 2.20%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.01%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 118,738.00 2.02%
usds
USDS (USDS) $ 1.00 0.05%
usdt0
USDT0 (USDT0) $ 0.999889 0.04%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 2.53%
mantle
Mantle (MNT) $ 2.11 12.93%
the-open-network
Toncoin (TON) $ 2.69 1.00%
crypto-com-chain
Cronos (CRO) $ 0.184682 3.04%
polkadot
Polkadot (DOT) $ 4.05 1.41%
whitebit
WhiteBIT Coin (WBT) $ 42.61 1.52%
monero
Monero (XMR) $ 331.97 0.53%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20 0.06%
uniswap
Uniswap (UNI) $ 7.77 0.65%
dai
Dai (DAI) $ 0.998604 0.08%
okb
OKB (OKB) $ 201.34 3.93%
aave
Aave (AAVE) $ 264.88 2.26%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.149173 14.90%
bitget-token
Bitget Token (BGB) $ 5.47 3.83%
near
NEAR Protocol (NEAR) $ 3.06 7.94%
zcash
Zcash (ZEC) $ 230.79 19.99%
ethena
Ethena (ENA) $ 0.522811 3.57%
pepe
Pepe (PEPE) $ 0.000009 3.36%
bittensor
Bittensor (TAO) $ 372.38 14.74%