North Korean IT workers used 30+ fake IDs to target crypto companies: report

2025/08/14 16:09

A compromised device from a North Korean IT worker has exposed the inner workings of the team behind the $680,000 Favrr hack and their use of Google tools to target crypto projects.

Summary
  • A compromised device belonging to a North Korean IT worker exposed the inner workings of threat actors.
  • Evidence shows operatives used Google powered tools, AnyDesk, and VPNs to infiltrate crypto firms.

According to on-chain sleuth ZachXBT, the trail began with an unnamed source who gained access to one of the workers’ computers, uncovering screenshots, Google Drive exports, and Chrome profiles that pulled back the curtain on how the operatives planned and carried out their schemes.

Drawing on wallet activity and matching digital fingerprints, ZachXBT verified the source material and tied the group’s cryptocurrency dealings to the June 2025 exploit of the fan-token marketplace Favrr. One wallet address, “0x78e1a,” showed direct links to stolen funds from the incident.

Inside the operation

The compromised device showed that the small team — six members in total — shared at least 31 fake identities. To land blockchain development jobs, they amassed government-issued IDs and phone numbers, even buying LinkedIn and Upwork accounts to complete their cover.

An interview script found on the device showed them boasting of experience at well-known blockchain firms, including Polygon Labs, OpenSea, and Chainlink.

Google tools were central to their organized workflow. The threat actors were found to be using drive spreadsheets to track budgets and schedules, while Google Translate bridged the language gap between Korean and English. 

Among the information pulled from the device was a spreadsheet that showed IT workers were renting computers and paying for VPN access to buy fresh accounts for their operations.

The team also relied on remote access tools such as AnyDesk, allowing them to control client systems without revealing their true locations. VPN logs tied their activity to multiple regions, masking North Korean IP addresses.

Additional findings revealed the group looking up ways to deploy tokens across different blockchains, scouting AI firms in Europe, and mapping out fresh targets in the crypto space.

North Korean threat actors use remote jobs

ZachXBT found the same pattern flagged in multiple cybersecurity reports — North Korean IT workers landing legitimate remote jobs to slip into the crypto sector. By posing as freelance developers, they gain access to code repositories, backend systems, and wallet infrastructure.

One document uncovered on the device was interview notes and preparation materials likely meant to be kept on-screen or nearby during calls with potential employers.

Clause de non-responsabilité : les articles republiés sur ce site proviennent de plateformes publiques et sont fournis à titre informatif uniquement. Ils ne reflètent pas nécessairement les opinions de MEXC. Tous les droits restent la propriété des auteurs d'origine. Si vous estimez qu'un contenu porte atteinte aux droits d'un tiers, veuillez contacter service@support.mexc.com pour demander sa suppression. MEXC ne garantit ni l'exactitude, ni l'exhaustivité, ni l'actualité des contenus, et décline toute responsabilité quant aux actions entreprises sur la base des informations fournies. Ces contenus ne constituent pas des conseils financiers, juridiques ou professionnels, et ne doivent pas être interprétés comme une recommandation ou une approbation de la part de MEXC.

Vous aimerez peut-être aussi

Kazakhstan to Move Reserve Wealth Into Crypto — Which Countries Showed Them the Way?

Kazakhstan to Move Reserve Wealth Into Crypto — Which Countries Showed Them the Way?

Kazakhstan is moving deeper into crypto, following the lead of sovereign funds in the US, Norway and the Middle East. It now plans to channel part of its gold and foreign exchange reserves, along with National Fund assets, into digital asset-related investments. The announcement came from National Bank Chairman Timur Suleimenov, who revealed at a recent press conference that Kazakhstan’s alternative portfolios will soon include exposure to crypto assets, local outlet Kursiv reported . These portfolios follow more aggressive investment strategies, aiming for higher returns while accepting a greater level of risk. Kazakhstan plans to allocate part of its national reserves to crypto assets and set up a national crypto reserve for confiscated assets, while exploring state-owned enterprises’ involvement in mining. https://t.co/KsrtgpATUe — Wu Blockchain (@WuBlockchain) July 14, 2025 Officials Cite Global Examples as Kazakhstan Mulls Crypto Exposure for Reserves “We looked at the experience of the Norwegian fund, the American experience, the experience of the Middle East funds,” Suleimenov said. “They have certain investments either in crypto assets directly or in ETFs and shares of companies that are closely related to crypto assets. They are quite small.” While the scale of Kazakhstan’s investment remains undecided, the country is clearly signaling its intent to join a growing club of sovereign wealth managers who see crypto as part of a diversified portfolio. Suleimenov stressed, however, that volatility remains a concern. “This is a difficult question, so there is no need to rush here,” he said. “Yes, such assets can bring high returns, but at the same time they are highly volatile.” Crypto Reserve to Be Funded by State Mining and Seized Crypto Holdings In a separate but related move, the National Bank confirmed plans to build a state crypto reserve. This new digital fund will store assets confiscated in criminal cases and could eventually receive contributions from state-backed crypto mining operations. Infrastructure to manage and safeguard this reserve is already under development. Suleimenov added that if enterprises mine crypto on behalf of the state, a portion of those earnings, through taxes or other obligations, could be funneled into the reserve. As Legal Infrastructure Grows, Kazakhstan Tightens Oversight on Unlicensed Crypto Activity Kazakhstan’s crypto ambitions go beyond investment. Last month, the government said it would formally introduce a legal framework for a state-run crypto reserve . The model will borrow international best practices from sovereign funds, including transparency, sound governance and long-term sustainability. Still, regulatory caution remains. Kazakhstan’s authorities have proposed new administrative and criminal penalties for transactions involving digital assets on the grey market. Currently, crypto trading is permitted only through licensed platforms based in the Astana International Financial Centre (AIFC). The central bank also plans to curb digital asset advertising to reduce retail exposure. Kazakhstan’s evolving relationship with crypto began in 2021, when Chinese miners relocated following Beijing’s clampdown on the industry. At its peak, the country handled over 27% of global Bitcoin mining activity. Although low energy costs initially made Kazakhstan attractive, the surge overwhelmed the power grid and exposed gaps in regulation. Now, with stricter rules and a clearer policy roadmap, Kazakhstan looks set to cement its place in the global crypto economy, both as a mining base and a sovereign investor.
Partager
CryptoNews2025/07/15 12:37