Scan to download
BTC $75,711.83 -2.37%
ETH $2,350.73 -3.37%
BNB $630.37 -1.80%
XRP $1.43 -4.16%
SOL $86.17 -3.50%
TRX $0.3297 +0.76%
DOGE $0.0947 -5.41%
ADA $0.2485 -4.96%
BCH $444.55 -2.34%
LINK $9.27 -4.13%
HYPE $44.01 -0.75%
AAVE $104.01 -11.19%
SUI $0.9549 -6.01%
XLM $0.1689 -3.37%
ZEC $320.52 -2.48%
BTC $75,711.83 -2.37%
ETH $2,350.73 -3.37%
BNB $630.37 -1.80%
XRP $1.43 -4.16%
SOL $86.17 -3.50%
TRX $0.3297 +0.76%
DOGE $0.0947 -5.41%
ADA $0.2485 -4.96%
BCH $444.55 -2.34%
LINK $9.27 -4.13%
HYPE $44.01 -0.75%
AAVE $104.01 -11.19%
SUI $0.9549 -6.01%
XLM $0.1689 -3.37%
ZEC $320.52 -2.48%

Analysis: North Korean hackers use inducements to run malicious programs to infiltrate systems, having stolen $1.6 billion in cryptocurrency this year

2025-08-05 09:05:28
Collection

ChainCatcher news, according to Decrypt, based on research by Google Cloud and cybersecurity company Wiz, North Korean hacker groups are infiltrating cloud systems through fake IT job offers, with an estimated $1.6 billion in cryptocurrency stolen by 2025. The research shows that a hacker team codenamed UNC4899 (also known as TraderTraitor, Jade Sleet, or Slow Pisces) is impersonating recruiters on social media to lure employees of target companies into running malicious programs, successfully breaching Google Cloud and AWS systems and hijacking cryptocurrency trading hosts. Wiz states that TraderTraitor represents a type of threat activity rather than a specific group, with North Korean-supported entities Lazarus Group, APT38, BlueNoroff, and Stardust Chollima being typical masterminds behind TraderTraitor attacks.

This attack pattern has been evolving since 2020: initially using JavaScript to build malicious cryptocurrency applications, introducing open-source code exploits in 2023, and focusing on attacking exchange cloud infrastructure in 2024, including an intrusion incident that caused a $305 million loss to Japan's DMM Bitcoin. Experts point out that North Korean hackers are among the first to adopt AI technology to generate phishing emails and malicious scripts, with their attack teams potentially numbering in the thousands.

app_icon
ChainCatcher Building the Web3 world with innovations.