By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn
Tech News

North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn

By Viral Trending Content 5 Min Read
Share
SHARE

Nov 23, 2024Ravie LakshmananArtificial Intelligence / Cryptocurrency

AI-Driven Scams

The North Korea-linked threat actor known as Sapphire Sleet is estimated to have stolen more than $10 million worth of cryptocurrency as part of social engineering campaigns orchestrated over a six-month period.

These findings come from Microsoft, which said that multiple threat activity clusters with ties to the country have been observed creating fake profiles on LinkedIn, posing as both recruiters and job seekers to generate illicit revenue for the sanction-hit nation.

Sapphire Sleet, which is known to be active since at least 2020, overlaps with hacking groups tracked as APT38 and BlueNoroff. In November 2023, the tech giant revealed that the threat actor had established infrastructure that impersonated skills assessment portals to carry out its social engineering campaigns.

Cybersecurity

One of the main methods adopted by the group for over a year is to pose as a venture capitalist, deceptively claiming an interest in a target user’s company in order to set up an online meeting. Targets who fall for the bait and attempt to connect to the meeting are shown error messages that urge them to contact the room administrator or support team for assistance.

Should the victim reach out to the threat actor, they are either sent an AppleScript (.scpt) file or a Visual Basic Script (.vbs) file depending on the operating system used to resolve the supposed connection issue.

Under the hood, the script is used to download malware onto the compromised Mac or Windows machine, ultimately allowing the attackers to obtain credentials and cryptocurrency wallets for subsequent theft.

Sapphire Sleet has been identified masquerading as a recruiters for financial firms like Goldman Sachs on LinkedIn to reach out to prospective targets and ask them to complete a skills assessment hosted on a website under their control.

“The threat actor sends the target user a sign-in account and password,” Microsoft said. “In signing in to the website and downloading the code associated with the skills assessment, the target user downloads malware onto their device, allowing the attackers to gain access to the system.”

Redmond has also characterized North Korea’s dispatching of thousands of IT workers abroad as a triple threat that makes money for the regime through “legitimate” work, allows them to abuse their access to get hold of intellectual property, and facilitates data theft in exchange for a ransom.

“Since it’s difficult for a person in North Korea to sign up for things such as a bank account or phone number, the IT workers must utilize facilitators to help them acquire access to platforms where they can apply for remote jobs,” it said. “These facilitators are used by the IT workers for tasks such as creating an account on a freelance job website.”

Cybersecurity

This includes creating bogus profiles and portfolios on developer platforms like GitHub and LinkedIn to communicate with recruiters and apply for jobs.

In some instances, they have also been found using artificial intelligence (AI) tools like Faceswap to modify photos and documents stolen from victims or show them against the backdrop of professional-looking settings. These pictures are then utilized on resumes or profiles, sometimes for several personas, that are submitted for job applications.

“In addition to using AI to assist with creating images used with job applications, North Korean IT workers are experimenting with other AI technologies such as voice-changing software,” Microsoft said.

“The North Korean IT workers appear to be very organized when it comes to tracking payments received. Overall, this group of North Korean IT workers appears to have made at least 370,000 US dollars through their efforts.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

IBM warns of critical API Connect auth bypass vulnerability

IBM warns of critical API Connect auth bypass vulnerability

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Drone service to deliver automated defibrillators

TAGGED: artificial intelligence, cryptocurrency, Cyber Security, Cybersecurity, Internet, LinkedIn, Malware, Microsoft, North Korea, social engineering
Share This Article
Facebook Twitter Copy Link
Previous Article XRP Price To $28: Wave Analysis Reveals When It Will Reach Double-Digits
Next Article The Two Papa John's pizzas ordered in 2010 now close to $1B mistake
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The Great Divide: When the mood overtakes the math
Business
Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale
Tech News
IBM warns of critical API Connect auth bypass vulnerability
Tech News
IBM warns of critical API Connect auth bypass vulnerability
Tech News
Pi Network suspends wallet payment requests after scammers drain millions
Crypto
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
Tech News
Chelsea’s inconsistencies are a troubling mess after Bournemouth draw – opinion
Sports

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The Great Divide: When the mood overtakes the math

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The Great Divide: When the mood overtakes the math
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?