Kraken Exposes North Korean Hacker Posing as a Job Candidate
By: bitcoin ethereum news|2025/05/02 21:45:02
0
Share
Kraken, a prominent cryptocurrency exchange, has uncovered a sophisticated infiltration attempt by a North Korean hacker posing as a job candidate. The security and recruitment teams advanced the candidate through the hiring process. The aim was to study their strategies and gather crucial insights. How a North Korean Hacker Tried to Infiltrate Kraken Kraken detailed the incident in a recent blog post on May 1. The hacker applied for an engineering role at the exchange, initially appearing as a legitimate candidate, allegedly named Steven Smith. However, several red flags emerged during the hiring process. “What started as a routine hiring process for an engineering role quickly turned into an intelligence gathering operation, as our teams carefully advanced the candidate through our hiring process to learn more about their tactics at every stage of the process,” Kraken noted. The candidate used a different name during the interview and kept switching voices, suggesting coaching. They applied using an email linked to North Korean hackers. Moreover, the Open-Source Intelligence gathering (OSINT) investigation uncovered the candidate’s involvement in a network of fake identities. “This meant that our team had uncovered a hacking operation where one individual had established multiple identities to apply for roles in the crypto space and beyond. Several of the names had previously been hired by multiple companies, as our team identified work-related email addresses linked to them. One identity in this network was also a known foreign agent on the sanctions list,” the blog read. Additionally, technical inconsistencies in their setup, like using remote, colocated Mac desktops accessed via a VPN and altered IDs, pointed to an infiltration attempt. This information confirmed that the candidate was likely a state-sponsored hacker. In a final interview with the candidate, Kraken’s Chief Security Officer, Nick Percoco, and some team members confirmed the company’s suspicions. The candidate’s failure to verify their location or answer questions about their city and citizenship revealed them as an impostor. “Their job is to start employment to steal intellectual property, steal money from those companies, take home a paycheck, and do it in a widespread way,” Percoco told CBS about the hackers. FinCEN Proposes Ban on Huione Group Over North Korean Ties Meanwhile, in another development, the US Financial Crimes Enforcement Network (FinCEN) has proposed banning Cambodia-based Huione Group from the US financial system. The department identified Huione as a key facilitator for North Korean hacker groups, including those involved in cyber heists and “pig butchering” cryptocurrency scams. “Huione Group has established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans,” Secretary of the Treasury Scott Bessent said. FinCEN accused the group of laundering over $4 billion in illicit funds between August 2021 and January 2025. According to the department, Huione’s network, including Huione Pay, Huione Crypto, and Haowang Guarantee, is a preferred marketplace for cryptocurrency criminals, offering services such as payment processing and an illicit online marketplace. “Today’s proposed action will sever Huione Group’s access to correspondent banking, degrading these groups’ ability to launder their ill-gotten gains. Treasury remains committed to disrupting any attempt by malicious cyber actors to secure revenue from or for their criminal schemes,” Bessent added. These incidents highlighted a pattern of North Korean cyberattacks on the cryptocurrency sector. In 2024, hackers stole over $659 million from crypto firms. According to a joint statement from the United States, Japan, and the Republic of Korea, North Korean hackers targeted the industry using tactics like social engineering and malware (e.g., TraderTraitor, AppleJeus). Additionally, North Korean IT workers were identified as insider threats to private sector companies. Previously, BeInCrypto reports have highlighted the notorious Lazarus Group, a North Korean state-sponsored hacking collective’s involvement in Bybit and Upbit thefts. Moreover, hacker groups from the country were also behind the Radiant Capital hack and the DMM Bitcoin exploit. In fact, recently, on-chain investigator ZachXBT uncovered significant North Korean involvement in decentralized finance (DeFi) protocols, with some of them relying on nearly 100% of their monthly volume/fees from the Democratic People’s Republic of Korea (DPRK). Disclaimer In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated. Source: https://beincrypto.com/north-korean-hacker-kraken-job-infiltration/
You may also like

What Is OpenClaw? How The AI Agent Could Automate Crypto Trading Through APIs
OpenClaw is a rapidly growing AI agent on GitHub that can automate tasks and even execute crypto trades through exchange APIs. Learn how OpenClaw works, how it connects to exchanges, and the risks traders should understand before using AI trading agents.

Morning News | Tencent is building an AI intelligent entity for WeChat; Meta announces acquisition of Moltbook; Nvidia plans to launch the AI agent open-source platform NemoClaw
Overview of Important Market Events on March 10

NVIDIA's Jensen Huang's new article: The "Five-Layer Cake" of AI
NVIDIA breaks down AI into a five-layer system consisting of energy, chips, infrastructure, models, and applications, and points out that every successful AI application will pull the entire industrial chain from computing power to electricity downward.

In-depth Analysis of ERC-8183: The Answer to the Trust Issue of Ethereum-Powered AI Agents
In the world of agents, one cannot conquer the world solely with reputation.

Stock Tokenization Revolution: Market Dynamics, Product Architecture, and Regulatory Moat Panorama Report
The integration of the $150 trillion global stock market with blockchain infrastructure is no longer just a proposition—it is happening.

The current Lobster Skill is just yesterday's Fruit Ninja, only meant to get you acquainted.
How Will Lobster Make Its Way into Our Lives?

Key Market Intelligence on March 10th, how much did you miss out on?
1. On-chain Funds: $51.2M USD inflow to Hyperliquid today; $51.2M USD outflow from Arbitrum
2. Biggest Gainers and Losers: $DRV, $OM
3. Top News: Middle East Conflict Sparks Stagflation Trading, Global Stock Markets Shed About $6 Trillion USD

IOSG: From Interest-Bearing Stablecoins to Crypto Credit Products
Bear Market Favors Stablecoin Yield Farming, Rise of Real World Asset (RWA) Lending with Interest-Bearing Stablecoins.

NVIDIA CEO Jensen Huang's Latest Article: The "Five Layers of AI"
NVIDIA breaks down AI into a five-level hierarchy of Energy, Silicon, Infrastructure, Models, and Applications, and points out that every successful AI application will pull through the entire stack from computation to power in the industry chain.

Daily Observation of Cryptocurrency Concept Stocks: Nasdaq Bets on Stocks on the Blockchain, Strategy Buys Another 17,994 BTC, ETH Treasury Stocks Enter Production Period
Traditional exchanges are beginning to embrace stock tokenization, while BTC treasury companies continue to increase their holdings through capital market instruments. ETH treasury companies, beyond Bitcoin, are also starting to validate the "holding + earning interest" balance sheet logic.

One-click onboarding to RootData, allowing project information to be accurately presented on over 200 platforms including Binance Wallet, Gate, TP, and more
Exchanging disclosure for trust, transparency is no longer a cost of the project, but a core asset for long-termists.

To the Builders who are still persevering in the crypto industry
Kydo deeply reflects on the dilemmas of the cryptocurrency industry: bidding farewell to the false prosperity of "selling infrastructure to developers" and proposing a new paradigm of using programmable capital to provide growth fuel for AI Agent companies.

Oil Price Cools Off, Crypto Bounces Back
Why Oil and Bitcoin Prices Always Move in Opposite Directions

a16z Releases Top 100 AI Applications List, Models Are Moving Out of the Browser and App
With the rise of video creation, Agent tools, and AI browsers, AI is evolving from a chat product into a new platform and operating environment.

If you only follow the news, you may have misconstrued this Iran conflict
With a Narrative-Driven Agenda, Western Media Falsifies War Coverage

ERC-8183: Write a Rule for a $3M On-Chain Agent Business
Before running in the Wild West of three million dollars, today, the rules have been written

AI Mistakenly 'Tips' $260,000, Makes It All Back in 24 Hours
AI Awakening seems to be really happening: they have already started to learn how to earn money on their own, and their money-earning ability may even surpass that of humans.

Arthur Hayes: Why is HYPE a 5x Moonshot?
Arthur Hayes' price target for HYPE in August 2026 is $150.
What Is OpenClaw? How The AI Agent Could Automate Crypto Trading Through APIs
OpenClaw is a rapidly growing AI agent on GitHub that can automate tasks and even execute crypto trades through exchange APIs. Learn how OpenClaw works, how it connects to exchanges, and the risks traders should understand before using AI trading agents.
Morning News | Tencent is building an AI intelligent entity for WeChat; Meta announces acquisition of Moltbook; Nvidia plans to launch the AI agent open-source platform NemoClaw
Overview of Important Market Events on March 10
NVIDIA's Jensen Huang's new article: The "Five-Layer Cake" of AI
NVIDIA breaks down AI into a five-layer system consisting of energy, chips, infrastructure, models, and applications, and points out that every successful AI application will pull the entire industrial chain from computing power to electricity downward.
In-depth Analysis of ERC-8183: The Answer to the Trust Issue of Ethereum-Powered AI Agents
In the world of agents, one cannot conquer the world solely with reputation.
Stock Tokenization Revolution: Market Dynamics, Product Architecture, and Regulatory Moat Panorama Report
The integration of the $150 trillion global stock market with blockchain infrastructure is no longer just a proposition—it is happening.
The current Lobster Skill is just yesterday's Fruit Ninja, only meant to get you acquainted.
How Will Lobster Make Its Way into Our Lives?