MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Report: North Korean IT Workers Exploiting Remote Jobs to Infiltrate Crypto Firms
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,884.00-0.09%
  • ethereumEthereum(ETH)$2,313.84-0.93%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.40-1.57%
  • binancecoinBNB(BNB)$626.02-0.85%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.16-1.30%
  • tronTRON(TRX)$0.3257820.67%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • dogecoinDogecoin(DOGE)$0.098261-0.34%
Crypto NewsBlockchain

Report: North Korean IT Workers Exploiting Remote Jobs to Infiltrate Crypto Firms

rahulbadiyafad150c105
Last updated: August 5, 2025 12:36 pm
rahulbadiyafad150c105
Published: 9 months ago
Share

North Korean IT workers are using fake identities to land remote jobs at crypto firms and steal millions in digital assets, cybersecurity researchers from Google Cloud and Wiz have revealed.

Contents
  • How did UNC4899 breach cloud environments?
  • A massive operation
  • Millions in Crypto Stolen

In separate reports, the firms detailed the activities of UNC4899—also known as TraderTraitor—a North Korean threat group linked to the country’s military intelligence.

Google Cloud’s H2 2025 Cloud Threat Horizons Report states that UNC4899 operates under the Reconnaissance General Bureau, North Korea’s primary foreign intelligence agency.

Active since at least 2020, the group has targeted the blockchain and cryptocurrency industries, employing sophisticated social engineering and cloud-focused attack techniques.

How did UNC4899 breach cloud environments?

Google detailed two separate incidents in which UNC4899 infiltrated cloud environments—one involving Google Cloud and the other AWS. In both cases, the hackers posed as freelance job recruiters and contacted employees via LinkedIn or Telegram.

After establishing contact, they tricked victims into running malicious Docker containers on their workstations. These containers launched downloaders and backdoors that connected to attacker-controlled infrastructure.

Within days, UNC4899 moved laterally across internal networks, harvested credentials, and identified systems involved in crypto transactions. In one instance, the group managed to disable multi-factor authentication (MFA) on a privileged Google Cloud account, gaining access to wallet-related services. After stealing crypto worth several million dollars, they re-enabled MFA to avoid detection.

In the AWS-related case, the attackers initially used stolen long-term access keys but were limited by the organization’s use of temporary credentials and MFA. They circumvented these defenses by stealing session cookies, allowing them to manipulate JavaScript files stored in AWS S3 buckets. These files were modified to reroute crypto wallet activity to attacker-controlled addresses, resulting in another multi-million-dollar theft.

A massive operation

Cloud security firm Wiz also investigated UNC4899 and released separate findings that support Google’s analysis.

According to Wiz, the group is known by several aliases—including Jade Sleet, Slow Pisces, and TraderTraitor—each representing broader tactics employed by various North Korean state-sponsored actors like Lazarus Group, BlueNoroff, and APT38.

While UNC4899 has been active since 2020, Wiz noted that fake job offers became a key tactic starting in 2023, primarily targeting employees at cryptocurrency exchanges.

Some of the most high-profile breaches linked to the group include the $305 million hack of Japan’s DMM Bitcoin and the massive $1.5 billion Bybit breach in late 2024.

Wiz warned that cloud infrastructure continues to be a common attack vector, as many crypto firms operate primarily in cloud-first environments with minimal on-premise defenses.

Millions in Crypto Stolen

Estimates of the financial impact vary, but all point to significant losses. Google and Wiz report that UNC4899 has stolen several million dollars in each incident, while broader assessments from private researchers and government agencies suggest the total is much higher.

A 2024 analysis by blockchain analytics firm Chainalysis revealed that North Korean hackers stole $1.34 billion in crypto that year alone. By mid-2025, Wiz researchers estimated that North Korea-linked threat actors had already siphoned off $1.6 billion in digital assets.

Meanwhile, independent blockchain investigator ZachXBT estimates that between 345 and 920 North Korean operatives have infiltrated crypto companies, collectively earning over $16 million in salaries since the beginning of 2025.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Dozens of New Investors Will Become Solana (SOL) Millionaires in 2025, But This Coin Will Create Hundreds More
$250B in stablecoins: The untold altseason story behind this capital shift!
Abu Dhabi Investment Council triples stake in Bitcoin ETF in Q3: Report
Palworld studio Pocketpair refuses to publish games that used generative AI
Vanguard may finally allow bitcoin ETFs
TAGGED:AltcoinBlockchaincrypto firmscryptocurrenciesITNorth KoreanScam

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article UNIUSDT Forming Bullish Continuation for BINANCE:UNIUSDT by Alpha-GoldFX
Next Article Crypto Prices Today: Bitcoin Price Holds $114,000, D0GE Surges 3%, Ethereum at $3,658
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d