FBI warns crypto firms of aggressive social engineering attacks

Share:

​The FBI warned today of North Korean hacking groups aggressively targeting cryptocurrency companies and their employees in sophisticated social engineering attacks to deploy malware designed to steal their crypto assets.

According to the FBI, their social engineering tactics are highly targeted and difficult to detect, even for those with advanced cybersecurity expertise.

Over the last several months, North Korean threat actors have been observed conducting extensive research on potential targets, focusing on individuals connected to cryptocurrency exchange-traded funds (ETFs) and other related financial products. This level of pre-operational staging suggests that they’re preparing for potential attacks on companies associated with cryptocurrency ETFs and similar assets.

The law enforcement agency also warned that organizations dealing with substantial quantities of cryptocurrency are also at risk of being targeted by North Korean hacking groups aiming to breach networks and steal funds.

Among the social engineering tactics these state-sponsored groups use, the FBI highlights their meticulously planned attacks, which start with identifying specific DeFi and cryptocurrency businesses to target. In the next attack stage, they target their employees in social engineering attacks that often involve offers of new employment or investment opportunities, leveraging detailed personal information to boost credibility and appeal.

“The actors usually communicate with victims in fluent or nearly fluent English and are well versed in the technical aspects of the cryptocurrency field,” the FBI warns.

“North Korean malicious cyber actors routinely impersonate a range of individuals, including contacts a victim may know personally or indirectly. Impersonations can involve general recruiters on professional networking websites, or prominent people associated with certain technologies.”

The attackers are well-versed in the cryptocurrency industry’s technical aspects and have also been observed using stolen images and professionally crafted websites to make their schemes look legitimate at first glance.

The FBI also provided a list of potential indicators of North Korean social engineering activity and the best practices that companies in the cryptocurrency industry and their employees should follow to lower the risk of compromise in such attacks.

Since the start of the year, the FBI has also warned of scammers posing as employees of crypto exchanges to target unsuspecting victims and cybercriminals posing as law firms offering cryptocurrency recovery services.

It also warned of fake remote job ads used to steal cryptocurrency and against using unlicensed cryptocurrency transfer services that can result in financial loss if law enforcement takes down these platforms.

Billions worth of cryptocurrency stolen since 2017

As Recorded Future analysts revealed in December, North Korean-backed state hacking groups like Kimsuky, Lazarus Group, Andariel, and others have stolen an estimated $3 billion worth of cryptocurrency in a long string of hacks targeting the crypto industry since 2017.

“In 2022 alone, North Korean threat actors were accused of stealing $1.7 billion in cryptocurrency, equivalent to 5% of the country’s economy or 45% of its military budget,” Recorded Future said.

Since stealing $82.7 million from South Korean exchanges Bithumb, Youbit, and Yapizon in 2017, North Korean hackers have been linked to many other crypto heists, including ones against the Harmony blockchain bridge ($100 million in losses), the Nomad bridge ($190 million in losses), the Qubit Finance bridge ($80 million in losses), Atomic Wallet ($35 million), AlphaPo ($60 million in two separate attacks), and CoinsPaid ($37 million).

The FBI also linked the hacking of Axie Infinity’s Ronin network bridge, the largest crypto hack ever, which resulted in the theft of $620 million, to North Korean hacking groups Lazarus and BlueNorOff (aka APT38).

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:44 am, Jan 24, 2025
weather icon 9°C
L: 9° | H: 10°
overcast clouds
Humidity: 91 %
Pressure: 996 mb
Wind: 14 mph WSW
Wind Gust: 24 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 6 km
Sunrise: 7:49 am
Sunset: 4:35 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 10°°C 1 mm 100% 24 mph 91 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 5°°C 1 mm 100% 11 mph 90 % 1010 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
2° | 7°°C 1 mm 100% 15 mph 97 % 1009 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 12 mph 98 % 991 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
5° | 7°°C 1 mm 100% 15 mph 92 % 999 mb 0 mm/h
Today 3:00 am
weather icon
9° | 10°°C 0.83 mm 83% 22 mph 91 % 996 mb 0 mm/h
Today 6:00 am
weather icon
9° | 10°°C 1 mm 100% 24 mph 89 % 995 mb 0 mm/h
Today 9:00 am
weather icon
10° | 11°°C 1 mm 100% 15 mph 85 % 994 mb 0 mm/h
Today 12:00 pm
weather icon
9° | 9°°C 0.8 mm 80% 17 mph 60 % 997 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 13 mph 50 % 999 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 0 mm 0% 9 mph 56 % 1002 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 63 % 1002 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 68 % 1000 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,380.79
1.38%
Ethereum(ETH)
€3,177.86
3.00%
XRP(XRP)
€2.96
-1.83%
Tether(USDT)
€0.96
0.05%
Solana(SOL)
€240.44
1.08%
USDC(USDC)
€0.96
-0.01%
Dogecoin(DOGE)
€0.333220
-1.78%
Shiba Inu(SHIB)
€0.000019
-1.03%
Pepe(PEPE)
€0.000014
0.07%
Peanut the Squirrel(PNUT)
€0.333452
-4.27%
Scroll to Top