Web Analytics
crypto.news
2025-04-01 17:51:23

‘We can’t defeat an enemy that we don’t know’: Researcher warns of North Korea’s changing crypto tactics

Paradigm security researcher Samczsun is raising concerns that North Korea’s cyber operations extend far beyond the notorious Lazarus Group. His warnings come as the crypto industry emerges from the recent Bybit hack , which reportedly involved a sophisticated compromise of SafeWallet infrastructure. This attack marked a departure from previous North Korean hacking incidents . Instead of directly targeting Bybit, the hackers managed to breach Safe{Wallet}. This shift in tactics highlights the growing sophistication of their strategies and raises significant concerns about the security of the broader cryptocurrency ecosystem. According to Samczsun , North Korean-backed cybercrime isn’t just the work of a single group, but rather a network of state-sponsored threat actors operating under different names. You might also like: Trump family reportedly seizes majority control of World Liberty Financial North Korea’s cyber warfare structure Samczsun has been analyzing North Korea’s cyber threat for years. He explains that referring to all North Korean cyber activity as the “Lazarus Group” oversimplifies a far more complex network. North Korea’s hacking operations are primarily run through the Reconnaissance General Bureau, an intelligence agency that oversees multiple hacking units. These include not only Lazarus Group but also APT38, AppleJeus, and other specialized teams. Each of these groups has a different focus. Lazarus Group, for example, is known for high-profile cyberattacks, including the 2014 Sony Pictures hack and the 2016 Bangladesh Bank heist. APT38 specializes in financial crimes, including bank fraud and cryptocurrency theft. “APT38,” Samczsun wrote, “which spun out of Lazarus Group in around 2016 in order to focus on financial crimes, targeting banks (such as the Bank of Bangladesh) first, then cryptocurrency later.” AppleJeus has targeted cryptocurrency users with malware disguised as trading apps. These groups work under the same government umbrella, helping to fund North Korea’s weapons programs and evade international sanctions. You might also like: Bitcoin in retirement plans? Sen. Tuberville revives crypto bill Crypto is now a North Korea target North Korea has turned to cryptocurrency as a major source of revenue. Unlike traditional finance, crypto transactions are decentralized and often more difficult to track or freeze. North Korean hackers exploit this by breaching exchanges, deploying malware, and using fake job offers to gain access to internal systems. One example is the case of “Wagemole” operatives — North Korean IT workers who infiltrate legitimate tech companies. These individuals appear to be regular employees but sometimes use their access to steal funds or compromise systems. This tactic was seen in the Munchables exploit , where an employee with ties to North Korea drained assets from the protocol. Another method is supply chain attacks, where hackers compromise software providers that serve cryptocurrency firms. In one case, AppleJeus hackers inserted malware into a widely used communications tool, affecting millions of users. In another, North Korean attackers breached a contractor working with Radiant Capital, gaining access through social engineering on Telegram, according to Samczsun. You might also like: Analysis: Bitcoin may see consolidation in April and May as selling pressure drops What this means for crypto Samczsun warned that North Korea’s cyber operations are evolving. The Bybit attack shows that hackers are now targeting infrastructure providers, not just exchanges. This means the entire crypto ecosystem — from wallets to smart contract platforms — could be at risk. For crypto users and businesses, the key takeaway is that North Korean cyber threats go beyond Lazarus Group and simple exchange hacks. The industry needs stronger security protocols, improved intelligence sharing, and greater awareness of social engineering threats.

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.