North Korean Operative Performs Social Engineering Attack on Kraken Crypto Exchange
By: zycrypto|2025/05/03 21:30:03
0
Share
Kraken, a crypto exchange, caught a North Korean agent trying to infiltrate the company through a job interview. Kraken noticed something was wrong when the interviewee used a different name from the one listed on his resume. The Kraken team then performed open-source intelligence scans on the interviewee and discovered he was associated with nefarious activity. After red flags started to show, the Kraken team continued interviewing the applicant to get as much information as possible on a potential security breach. The applicant applied for the job after a regular recruitment process. The applicant, however, slipped up on the first call and gave a different name to the one on his resume. The interviewee further displayed signs of having someone coach him during the interview. Kraken, however, was aware of North Korean operatives targeting crypto exchanges, thanks to a partner company giving Kraken the heads-up. For example, other crypto companies were aware of the email used by the interviewee because it was flagged as being associated with disreputable activities. Kraken performed open intelligence analysis on the information they provided, including the email address, and discovered that it had been used multiple times by other employees hired at crypto companies. Many signs were pointing to an organized campaign. The applicant routed his internet traffic through a stand-alone Macintosh workstation to disguise his location. Open-source intelligence linked the applicant’s email to a known data breach. Even the applicant’s identity could be traced to a possible identity theft. Needless to say, the applicant was brazen in his attempts to infiltrate Kraken. Crypto companies like Kraken often employ remote workers to maintain their exchanges. Although the process can be incredibly convenient for workers and managers, there are also a few security holes. Kraken has learned a valuable lesson during this experience, strengthening its resolve to verify new employees rather than trust them at face value. The North Korean operatives could have easily infiltrated the company and used their position to inject malware into the company’s software or even steal valuable information. The infiltration attempt was relatively sophisticated, so, surprisingly, the applicant made such an obvious mistake, using a different name from the one listed on his resume. State-sponsored hackers, notably from North Korea, have surprised the world with multiple attacks. They will probably continue their attempts to breach crypto networks for some time. North Korean hackers have tried many exploits, including malware, phishing attacks, and now a social engineering attempt. There is a new trend of North Korean hackers infiltrating systems to perform exploits from within the system. From recent events, one such example of this trend includes the North Korean Lazarus Group creating shell companies in America to exploit job applicants. Usually, the goal is to steal cryptocurrencies because they are easy to conceal and transfer across borders, even to North Korea. Social Engineering attacks may continue to become a mainstay with the crypto industry, compelling many crypto investors to be extra vigilant when communicating online.
You may also like

Interview with Hyperliquid Founder Jeff Yan: Crypto and DeFi Are in Our DNA, Never Compromising on Trust
In the era of AI acceleration, if the financial system does not upgrade to a blockchain-based, programmable, open architecture, there will be no place for humans in the future financial world.

$1 Billion Free Lottery, Kalshi Launches Prediction Challenge
Good news, the jackpot is real; bad news, the odds are 1 in 120,000,000,000...

SlowMist: Is it Really Safe to Entrust Your Money to an AI Agent like "Lobster"?
The API permission boundary both determines what the Agent can do and the extent to which potential losses may escalate in the event of a security incident.

Regulation, Insiderism, and Essence: The Story Behind Kalshi's $20 Billion Valuation
80% of users are just consuming information

You Have Been Training Google's AI for Free for 15 Years, and You Didn't Even Know
You proved you are human, only to end up making yourself replaceable.
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.

How to Trade Cryptocurrency Without App Store: Instant Browser Crypto Trading on WEEX
Trade crypto instantly without downloading an app. Use WEEX H5 to access spot and futures trading directly in your browser with fast execution, real-time risk control, and seamless experience across mobile, tablet, and desktop. Supports Bitcoin, Ethereum, and more.

From OKX to Bybit, exchanges are changing tires on the highway at high speed
In the current context of tightening global regulations, if one can directly enter the market with a partner that has already established a compliance system, obtaining federal license endorsement, the credibility of a listed company, and access to banking cooperation channels, the cost is merely gi...

A Brief History and Future of Perpetual Contracts
Decentralized perpetual contract exchanges, such as Hyperliquid, are replacing traditional derivatives with structural advantages, becoming trillion-dollar financial platforms that attract global assets.

AI Agent Gets ID and Wallet on the Same Day | Rewire News Morning Brief
Agent infrastructure for the economy is forming faster than anyone expected

IOSG: Power Flexibility Paradigm Shift: From Macro Assets to Distributed Intelligence Layer
The power system is being asked to perform a task it was not designed to do.

Murata 35% Price Increase Explained: A Capacitor that Gives AI Empire a Cold
Choosing to raise at this point in time has a clear financial incentive

MiniMax: A Henan County Youth and His 300 Billion
Money, cards, and people were scarce, yet it spurred the highest levels of engineering prowess and architectural innovation.

From Abandoned Project to Sky-High Target, Mastercorp Acquires BVNK for $1.8 Billion
The stablecoin is no longer a competitor to the card networks, but has instead been assimilated into its underlying network as a highly complementary business subset.

Is Polymarket's Pricing Accurate? I Simulated a Crisis with 200 Agents to Find Out
The more participants, the richer the discussion structure, and the more valuable the resulting signal.

A Decade of Regulation Finally Clarified, Victory for Crypto-Native Logic
Three Charts to Explain What's in This 68-Page Document

The United States Establishes the "Five Categories Law" for Cryptographic Assets: A Summary to Understand the New Regulatory Framework
Is the "Wild West" era of cryptocurrency assets officially coming to an end?

Morning Report | Mastercard plans to acquire BVNK for up to $1.8 billion; Solana Foundation launches aggregator Tokens on Solana; Bitcoin sees its first 8 consecutive rises in four years
Overview of Important Market Events on March 17
Interview with Hyperliquid Founder Jeff Yan: Crypto and DeFi Are in Our DNA, Never Compromising on Trust
In the era of AI acceleration, if the financial system does not upgrade to a blockchain-based, programmable, open architecture, there will be no place for humans in the future financial world.
$1 Billion Free Lottery, Kalshi Launches Prediction Challenge
Good news, the jackpot is real; bad news, the odds are 1 in 120,000,000,000...
SlowMist: Is it Really Safe to Entrust Your Money to an AI Agent like "Lobster"?
The API permission boundary both determines what the Agent can do and the extent to which potential losses may escalate in the event of a security incident.
Regulation, Insiderism, and Essence: The Story Behind Kalshi's $20 Billion Valuation
80% of users are just consuming information
You Have Been Training Google's AI for Free for 15 Years, and You Didn't Even Know
You proved you are human, only to end up making yourself replaceable.
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.