Hackers norte -coreanos: a nova face da espionagem cibernética 🕵️‍♂️💻

Insights -chave:

  • O governo dos EUA acaba de sancionar dois indivíduos e quatro entidades russas ligadas à campanha Cyber ​​Crypto.
  • agentes de ataque cibernético norte-coreano estão cada vez mais favorecendo a infiltração sobre hackers de força bruta.
  • Eles foram responsáveis ​​por bilhões serem roubados do espaço criptográfico apenas em vários eventos este ano.

Os Estados Unidos impuseram novas sanções a uma nova operação cibernética apoiada pela Coréia do Norte. Esse grupo supostamente está usando pedidos de emprego remotos para funilar fundos de criptografia roubados no programa de armas nucleares da Kim Jong Un. 🚀💰

⚡️ CRISE À VISTA: Dólar ameaça derrubar o Real! VEJA O ALERTA!

Ler Análise Urgente!

Os últimos desenvolvimentos agora mostram que os ataques cibernéticos norte-coreanos estão aumentando de ataques cibernéticos de força bruta em infiltração e roubando fundos por dentro. Aqui estão os detalhes.


E aí, pessoal! Prontos para embarcar na viagem maluca das notícias de cripto? No nosso canal do Telegram, vamos explorar o mundo das criptomoedas com leveza e bom humor. É como um papo de bar sobre Bitcoin, só que sem a ressaca no dia seguinte! 😄 Junte-se a nós agora e vamos desvendar esse universo juntos! 💸🚀

Junte-se ao Telegram


Infiltração através do emprego, não apenas hackers de criptografia

Os ataques cibernéticos da Coréia do Norte fizeram manchetes muitas vezes no passado por prejudicar hacks, incluindo o notório envolvimento do grupo Lazarus em alguns dos maiores roubos de criptografia até o momento.

No entanto, de acordo com as descobertas recentes da empresa de análise do Tesouro e Blockchain dos EUA, TRM Labs, o regime agora está investindo pesadamente em outros métodos. Um dos mais perturbadores deles é o uso de trabalhadores de TI altamente qualificados que se apresentam como contratados remotos. 🕵️‍♂️💻

Hoje, o Escritório de Controle de Ativos Estrangeiros do Tesouro está tomando medidas para impedir indivíduos e entidades que estão permitindo a República Popular Democrática da Coréia (RPDC), esquemas de trabalhadores de TI.

A RPDC gera receita significativa para seus programas de mísseis de armas de fogo e balísticos por…

– Departamento do Tesouro (@ustrasury)

These contractors are used to secure employment in US-based blockchain and crypto companies and don’t just steal data: Instead, they pose as real employees by assuming the identities of US citizens. They exploit company access, plant malware and collect salaries that are funneled back to the North Korean government.

According to reports, their work reportedly spans across sectors including business software, health and fitness apps, social networking, sports, entertainment, and crypto exchanges. 🏋️‍♂️📱🎮

Sanctions Target Individuals and Front Companies

On July 8, the US Treasury’s Office of Foreign Assets Control (OFAC) announced sanctions against two individuals and four Russian entities linked to the crypto cyber campaign.

Among those named was Song Kum Hyok, a North Korean operative and a member of the Andariel hacking group. For context, the Andariel hacking group is part of Kim Jong Un’s military intelligence wing known as the Reconnaissance General Bureau. 🕵️‍♂️💥

Song is accused of masterminding a massive identity theft campaign as far back as 2022. Then, he stole names, Social Security numbers, and other personal information from American citizens.

These stolen identities were then used to disguise North Korean IT workers as real job applicants.

The workers, once hired, would share the income with Song and other operatives. In some cases, they would even go as far as inserting malware into company systems.

Another sanctioned individual was Gayk Asatryan, a Russian national who allegedly signed a 10-year agreement with North Korean trading firms in 2024.

This afternoon the sanctioned a key North Korean cyber actor for running an IT worker scheme using fake US IDs to funnel funds to the DPRK. For more check out our blogpost here:

— TRM Labs (@trmlabs)

He formed a network under this deal. It was called the “Asatryan IT Worker Network”, and would host up to 30 North Korean IT specialists in Russia. He helped them with several tasks, including helping them secure jobs in Western tech firms.

And so far, the four sanctioned individuals tied to Asatryan are now barred from accessing any assets within the US. They also face criminal penalties for any ongoing or future transactions with US companies. 🚫💰

All To Fund Weapons of Mass Destruction

US officials believe the ultimate goal of this cyber hacking scheme that has spanned years, is to support North Korea’s weapons development. Treasury Deputy Secretary Michael Faulkender stated that thousands of North Korean IT workers, mostly stationed in Russia and China are actively targeting crypto companies in wealthier nations.

Their income, often obtained under fake identities, is funneled back to the regime to pay for its arsenal and nuclear warheads. 🚀💥

“The Kim regime is determined to evade sanctions using every digital loophole it can find,” Faulkender emphasized. “From digital asset theft to fake job applications, their tactics are evolving. We are using all available tools to disrupt these networks.”

Massive Losses in the Crypto Sector

According to TRM Labs, North Korean bad actors were responsible for $1.6 billion in theft from crypto firms during the first half of the year alone. This accounts for over three-quarters of the total $2.1 billion stolen across 75 major crypto hacks in that timeframe. 💸🔒

While exchange hacks still remain a risk, other strategies like the IT worker infiltration are becoming more and more preferred. This is due to their lower visibility and high return.

Similarly, on June 30, four North Korean nationals were charged with wire fraud and money laundering. This is after allegedly posing as remote workers at blockchain firms in the US and Serbia. 🕵️‍♂️💻💰

Earlier on June 5, the DOJ moved to seize $7.74 million in frozen crypto tied to North Korean IT workers. According to the FBI, the entire moneymaking operation could be worth hundreds of millions of dollars. This is with funds being routed to the regime across Russia, China, and even the US. 🚀💥💰

2025-07-09 15:44