By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: North Korean hackers set up 3 shell companies to scam crypto devs
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Crypto > North Korean hackers set up 3 shell companies to scam crypto devs
Crypto

North Korean hackers set up 3 shell companies to scam crypto devs

By Viral Trending Content 4 Min Read
Share
SHARE

A subgroup of the North Korea-linked hacker organization Lazarus set up three shell companies, two in the US, to deliver malware to unsuspecting users.

The three sham crypto consulting firms — BlockNovas, Angeloper Agency and SoftGlide — are being used by the North Korean hacker group Contagious Interview to distribute malware through fake job interviews, Silent Push Threat Analysts said in an April 24 report.

Silent Push senior threat analyst Zach Edwards said in an April 24 statement to X that two shell companies are registered as legitimate businesses in the United States.

“These websites and a huge network of accounts on hiring / recruiting websites are being used to trick people into applying for jobs,” he said.

“During the job application process an error message is displayed as someone tries to record an introduction video. The solution is an easy click fix copy and paste trick, which leads to malware if the unsuspecting developer completes the process.”

<em>During the sham job interview, an error message is displayed, requiring the user to click, copy, and paste to fix it, which leads to the malware infection. Source: </em><a data-ct-non-breakable="null" href="https://x.com/thezedwards/status/1915490574431642066/photo/1" rel="null" target="null" text="null" title="null"><em>Zach Edwards</em></a>

Three strains of malware — BeaverTail, InvisibleFerret and Otter Cookie — are being used according to Silent Push.

BeaverTail is malware primarily designed for information theft and to load further stages of malware. OtterCookie and InvisibleFerret mainly target sensitive information, including crypto wallet keys and clipboard data.

Silent Push analysts said in the report that hackers use GitHub, job listing’s and freelancer websites to look for victims.

AI used to create fake employees 

The ruse also involves the hackers using AI-generated images to create profiles of employees for the three front crypto companies and stealing images of real people.

“There are numerous fake employees and stolen images from real people being used across this network. We’ve documented some of the obvious fakes and stolen images, but it’s very important to appreciate that the impersonation efforts from this campaign are different,” Edwards said.

“In one of the examples, the threat actors took a real photo from a real person, and then appeared to have run it through an AI image modifier tool to create a subtly different version of that same image.”

Related: Fake Zoom malware steals crypto while it’s ‘stuck’ loading, user warns

This malware campaign has been ongoing since 2024. Edwards says there are known public victims.

Silent Push identified two developers targeted by the campaign; one of them reportedly had their MetaMask wallet compromised.

The FBI has since shut down at least one of the companies.

“The Federal Bureau of Investigation (FBI) acquired the Blocknovas domain, but Softglide is still live, along with some of their other infrastructure,” Edwards said.

At least three crypto founders have reported in March that they foiled an attempt from alleged North Korean hackers to steal sensitive data through fake Zoom calls.

Groups such as the Lazarus Group are the prime suspects in some of the biggest cyber thefts in Web3, including the Bybit $1.4 billion hack and the $600 million Ronin network hack.

Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis

You Might Also Like

Polymarket Sees Record $153M Daily Volume After Chainlink Integration

Elon Musk’s xAI sues Colorado arguing its AI rules restrict speech

OKX Ventures, HashKey back VPBank-linked CAEX for Vietnam crypto pilot push

Bitcoin Figure Adam Back Denies Being Satoshi Nakamoto

CIA to integrate AI ‘co-workers’ to process intelligence, catch spies

TAGGED: Crypto, Crypto News, News
Share This Article
Facebook Twitter Copy Link
Previous Article JD.com’s delivery clash with Meituan may worsen $70 billion rout
Next Article Mansfield releases statement on player given prison sentence for causing the death of cyclist
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?