North Korean IT workers used 30+ fake IDs to target crypto companies: report

2025/08/14 16:09

A compromised device from a North Korean IT worker has exposed the inner workings of the team behind the $680,000 Favrr hack and their use of Google tools to target crypto projects.

Summary
  • A compromised device belonging to a North Korean IT worker exposed the inner workings of threat actors.
  • Evidence shows operatives used Google powered tools, AnyDesk, and VPNs to infiltrate crypto firms.

According to on-chain sleuth ZachXBT, the trail began with an unnamed source who gained access to one of the workers’ computers, uncovering screenshots, Google Drive exports, and Chrome profiles that pulled back the curtain on how the operatives planned and carried out their schemes.

Drawing on wallet activity and matching digital fingerprints, ZachXBT verified the source material and tied the group’s cryptocurrency dealings to the June 2025 exploit of the fan-token marketplace Favrr. One wallet address, “0x78e1a,” showed direct links to stolen funds from the incident.

Inside the operation

The compromised device showed that the small team — six members in total — shared at least 31 fake identities. To land blockchain development jobs, they amassed government-issued IDs and phone numbers, even buying LinkedIn and Upwork accounts to complete their cover.

An interview script found on the device showed them boasting of experience at well-known blockchain firms, including Polygon Labs, OpenSea, and Chainlink.

Google tools were central to their organized workflow. The threat actors were found to be using drive spreadsheets to track budgets and schedules, while Google Translate bridged the language gap between Korean and English. 

Among the information pulled from the device was a spreadsheet that showed IT workers were renting computers and paying for VPN access to buy fresh accounts for their operations.

The team also relied on remote access tools such as AnyDesk, allowing them to control client systems without revealing their true locations. VPN logs tied their activity to multiple regions, masking North Korean IP addresses.

Additional findings revealed the group looking up ways to deploy tokens across different blockchains, scouting AI firms in Europe, and mapping out fresh targets in the crypto space.

North Korean threat actors use remote jobs

ZachXBT found the same pattern flagged in multiple cybersecurity reports — North Korean IT workers landing legitimate remote jobs to slip into the crypto sector. By posing as freelance developers, they gain access to code repositories, backend systems, and wallet infrastructure.

One document uncovered on the device was interview notes and preparation materials likely meant to be kept on-screen or nearby during calls with potential employers.

Aviso legal: Los artículos republicados en este sitio provienen de plataformas públicas y se ofrecen únicamente con fines informativos. No reflejan necesariamente la opinión de MEXC. Todos los derechos pertenecen a los autores originales. Si consideras que algún contenido infringe derechos de terceros, comunícate con service@support.mexc.com para solicitar su eliminación. MEXC no garantiza la exactitud, la integridad ni la actualidad del contenido y no se responsabiliza por acciones tomadas en función de la información proporcionada. El contenido no constituye asesoría financiera, legal ni profesional, ni debe interpretarse como recomendación o respaldo por parte de MEXC.

También te puede interesar

South Korean Court Jails Two Members of Cross-border USDT Money Laundering Ring

South Korean Court Jails Two Members of Cross-border USDT Money Laundering Ring

A South Korean court has jailed two Vietnamese nationals for using Tether (USDT) to power a cross-border money laundering scheme. The duo used the USD-pegged stablecoin to smuggle funds raised from voice phishing scams overseas. USDT Money Laundering Ring: Defendants Jailed for Two Years The South Korean media outlet Financial News reported that the Criminal Division of the Seoul Eastern District Court’s Presiding Judge Lee Jeong-hyeong sentenced the duo to two years in prison each on June 22. The Seoul Eastern District Court, in Seoul, South Korea. (Source: Pectus Solentis [CC BY-SA 4.0]) The defendants were identified as a college student surnamed Duong (23) and an unemployed individual surnamed Pham (also 23). The court found both individuals guilty of violating the Special Act on Prevention of Telecommunications and Financial Fraud and Refund of Damages. Prosecutors explained that Duong and Pham first made contact with the voice phishing scam ring in October last year. The ring recruited both via a Telegram open chat room. The ring’s organizers told Duong and Pham that they were to receive the proceeds of voice phishing scams in Korean won. The duo was then instructed to use this money to buy USDT, which they then sent to a crypto wallet held by a member of a voice phishing gang who was residing in Vietnam. The ring paid both Duong and Pham commission fees of 50,000 won ($36.44) to 100,000 won ($72.88) per 10 million won ($7,288) worth of USDT they sent. In a bold play to secure Korea’s position among the global AI elite, President Lee Jae Myung kicked off his term with a visit to the launch site of a mega-scale AI data center. #AIdatacenter https://t.co/gGHvfjNBvw — The Korea JoongAng Daily (@JoongAngDaily) June 22, 2025 ‘Hash Sentence Inevitable,’ Judge Explains The court heard that the voice phishing ring succeeded in duping South Korea-based victims out of thousands of dollars’ worth of cash transfers. The ring’s employees called people pretending to be credit card delivery workers, insurance company employees, National Tax Service staffers, and even public prosecutors. They usually told potential victims that they were calling to check the safety of their bank accounts. The ring used a range of money laundering techniques, using other accomplices from Uzbekistan and Vietnam. The judge said that the court had not handed out a harsher sentence because neither of the defendants had criminal records in South Korea. But Lee added: “Even if the defendants did not orchestrate the crime, they must be severely punished. They played an essential role in the crime, acting as intermediaries. They have also not made any special efforts to help compensate the victims for the damages incurred.” USDT-related crime is on the rise in South Korea, as the coin’s popularity in the nation continues to grow. This year has seen a sharp rise in bogus USDT-themed over-the-counter deals and related thefts .
Compartir
CryptoNews2025/06/23 07:30
SEC Is Mobilizing All Branches To Make U.S. A Global Crypto Hub, Chair Paul Atkins Says

SEC Is Mobilizing All Branches To Make U.S. A Global Crypto Hub, Chair Paul Atkins Says

United States Securities and Exchange Commission (SEC) Chair Paul Atkins says the agency is “mobilizing” to make the U.S. a global hub for digital assets, the federal regulator told Fox News reporter Maria Bartiromo in an interview on August 15. SEC ‘Mobilizing’ to Make America Crypto Capital, Paul Atkins Says During his appearance on the media outlet on Friday, Atkins doubled down on his commitment to following through with U.S. President Donald Trump’s plan to make the U.S. a worldwide digital asset epicenter. SEC Chairman Paul Atkins announces “we are mobilizing at the SEC all our divisions and offices to make President Trump's vision for making America the crypto capital of the world a reality.” Ondo is looking forward to contributing to the President's vision with our tokenized… pic.twitter.com/I98btI8qj4 — Ondo Finance (@OndoFinance) August 15, 2025 “A couple weeks ago, the administration issued the President’s Working Group report on digital assets in the United States and there are clear directions from the SEC…for us to go forward and make what the president has announced as his intention to make America the crypto capital of the world,” Atkins said. “We’re mobilizing at the SEC all the different divisions and offices to focus on making that announcement become reality,” he added. SEC Shifts Away From Regulation-By-Enforcement Approach News of Atkins’ latest interviews comes just days after he reaffirmed his dedication to shifting the SEC away from its prior regulation-by-enforcement approach to the blockchain sector . In an August 11 X post, SEC Commissioner Hester Peirce praised the agency dropping its case against crypto platform Ripple. “A welcome development for many reasons, including that minds once occupied with litigation now can concentrate on creating a clear regulatory framework for crypto,” Peirce wrote . “Commissioner Peirce is right. With this chapter closed, we now have an opportunity to shift our energy from the courtroom to the policy drafting table,” Atkins said. “Our focus should be on building a clear regulatory framework that fosters innovation while protecting investors.” In short, Atkins’ message is clear: the SEC is shifting gears from fighting crypto in courtrooms to crafting rules that could cement America’s place as the world’s digital asset powerhouse.
Compartir
CryptoNews2025/08/16 06:45