By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack
Tech News

DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack

By Viral Trending Content 6 Min Read
Share
SHARE

Apr 23, 2025Ravie LakshmananMalware / Cryptocurrency

TRON Phishing Attack

Multiple threat activity clusters with ties to North Korea (aka Democratic People’s Republic of Korea or DPRK) have been linked to attacks targeting organizations and individuals in the Web3 and cryptocurrency space.

“The focus on Web3 and cryptocurrency appears to be primarily financially motivated due to the heavy sanctions that have been placed on North Korea,” Google-owned Mandiant said in its M-Trends report for 2025 shared with The Hacker News.

“These activities aim to generate financial gains, reportedly funding North Korea’s weapons of mass destruction (WMD) program and other strategic assets.”

The cybersecurity firm said DPRK-nexus threat actors have developed custom tools written in a variety of languages such as Golang, C++, and Rust, and are capable of infecting Windows, Linux, and macOS operating systems.

At least three threat activity clusters it tracks as UNC1069, UNC4899, and UNC5342 have been found to target members of the cryptocurrency and blockchain-development community, particularly focusing on developers working on Web3-adjacent projects to obtain illicit access to cryptocurrency wallets and to the organizations that employ them.

A brief description of each of the threat actors is below –

  • UNC1069 (Active since at least April 2018), which targets diverse industries for financial gain using social engineering ploys by sending fake meeting invites and posing as investors from reputable companies on Telegram to gain access to victims’ digital assets and cryptocurrency
  • UNC4899 (Active since 2022), which is known for orchestrating job-themed campaigns that deliver malware as part of a supposed coding assignment and has previously staged supply chain compromises for financial gain (Overlaps with Jade Sleet, PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899)
  • UNC5342 (Active since January 2024), which is also known for employing job-related lures to trick developers into running malware-laced projects (Overlaps with Contagious Interview, DeceptiveDevelopment, DEV#POPPER, and Famous Chollima)

Another North Korean threat actor of note is UNC4736, which has singled out the blockchain industry by trojanizing trading software applications and has been attributed to a cascading supply chain attack on 3CX in early 2023.

Cybersecurity

Mandiant said it also identified a separate cluster of North Korean activity tracked as UNC3782 that conducts large-scale phishing campaigns targeting the cryptocurrency sector.

“In 2023, UNC3782 conducted phishing operations against TRON users and transferred more than $137 million USD worth of assets in a single day,” the company noted. “UNC3782 launched a campaign in 2024 to target Solana users and direct them to pages that contained cryptocurrency drainers.”

Cryptocurrency theft is one of the several means the DPRK has pursued to sidestep international sanctions. At least since 2022, an active threat cluster dubbed UNC5267 has dispatched thousands of its citizens to secure remote employment jobs at companies in the U.S., Europe, and Asia while primarily residing in China and Russia.

A major chunk of the IT workers are said to be affiliated with the 313 General Bureau of the Munitions Industry Department, which is responsible for the nuclear program in North Korea.

The North Korean IT workers, in addition to making use of stolen identities, have utilized completely fabricated personas to support their activities. This is also complemented by the use of real-time deepfake technology to create convincing synthetic identities during job interviews.

“This offers two key operational advantages. First, it allows a single operator to interview for the same position multiple times using different synthetic personas,” Palo Alto Networks Unit 42 researcher Evan Gordenker said.

“Second, it helps operatives avoid being identified and added to security bulletins and wanted notices. Combined, it helps DPRK IT workers enjoy enhanced operational security and decreased detectability.”

The DPRK IT worker scheme, which takes insider threats to a whole new level, is engineered to funnel back their salaries to Pyongyang to advance its strategic goals, maintain long-term access to victim networks, and even extort their employers.

Cybersecurity

“They have also intensified extortion campaigns against employers, and they’ve moved to conduct operations in corporate virtual desktops, networks, and servers,” Google Threat Intelligence Group (GTIG)’s Jamie Collier and Michael Barnhart said in a report last month.

“They now use their privileged access to steal data and enable cyberattacks, in addition to generating revenue for North Korea.”

In 2024, Mandiant said it identified a suspected DPRK IT worker using at least 12 personas while seeking employment in the U.S. and Europe, highlighting the effectiveness of turning to such unconventional methods to infiltrate organizations under false pretenses.

“In at least one instance, two false identities were considered for a job in a U.S. company, with one DPRK IT worker winning out over the other,” the threat intelligence firm pointed out. In another instance, “four suspected DPRK IT workers had been employed within a 12-month period at a single organization.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Samsung Galaxy A36 Black Friday Deal Saves You £150

This Lightweight Laptop Is Almost Half Off

New SonicWall SonicOS flaw allows hackers to crash firewalls

lynx, beavers, and aurochs benefit landscapes

Dell Pro Max 18 Plus: Desktop Power in a Portable Laptop

TAGGED: Blockchain, cryptocurrency, Cyber Security, Cybersecurity, deepfake, insider threat, Internet, Malware, North Korea, phishing, supply chain attack
Share This Article
Facebook Twitter Copy Link
Previous Article Wall Street rises in a worldwide rally after Trump softens his tough talk on trade and the Fed
Next Article Here’s why Trump meme coin exploded 70% today
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Kevin Spacey Then & Now: Pictures of the Actor Over the Years
Celebrity
Kirby Air Riders Just Dropped, And It Might Be 2025’s Sleeper Giant
Gaming News
Nillion (NIL) price crashes 50% after unauthorized market-maker sell-off
Crypto
Bitcoin Long-Term Holders Keep Offloading Bags As Market Weakness Persists
Crypto
Nvidia relief won't be enough to dispel tech-bubble angst
Business
Samsung Galaxy A36 Black Friday Deal Saves You £150
Tech News
What’s causing the crypto sell-off, who is losing, and will it last?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Kevin Spacey Then & Now: Pictures of the Actor Over the Years

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Kevin Spacey Then & Now: Pictures of the Actor Over the Years
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?