🎁 Ace quick missions & earn crypto rewards while gaining real-world Web3 skills. JOIN NOW! 🔥

Leaked Device Reveals North Korea's Crypto Freelance Trick

Key Takeaways

  • ​A North Korean group used over 30 fake identities to get remote crypto jobs through LinkedIn and UpWork;
  • The team coordinated tasks using Google tools and masked their location with VPNs and AnyDesk;
  • One linked wallet was tied to a $680,000 hack, while leaked searches showed interest in AI and blockchain tech.

Ace quick missions & earn crypto rewards while gaining real-world Web3 skills. Participate Now! 🔥

Leaked Device Reveals North Korea's Crypto Freelance Trick

An August 13 report by blockchain investigator ZachXBT has revealed how a North Korean hacking group used fake identities and freelance job platforms to secure crypto-related roles.

The findings come from a hacked device belonging to one of the group’s members.

Screenshots from the compromised system exposed six individuals, believed to be connected to a $680,000 exploit in June, coordinated their operations using familiar tools and rented equipment.

What is a Cryptocurrency: For Beginners (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe - We publish new crypto explainer videos every week!

The group created and managed over 30 false identities, complete with forged documents and paid accounts on LinkedIn and UpWork. These profiles were then used to apply for remote jobs in the blockchain industry.

One member was found to have gone through an interview process for a developer role at Polygon MATIC $0.2515 Labs, while others submitted applications claiming to have worked at platforms like OpenSea and Chainlink LINK $23.63 .

Once hired, the team relied on remote access software such as AnyDesk and used VPNs to hide their actual locations. Their daily workflow was organized through Google’s ecosystem, including Drive, Chrome profiles, and calendar tools, often supported by Google Translate to assist with English communication.

Payments for their services typically flowed through Payoneer and were later converted into crypto. One wallet address, labeled "0x78e1a", was directly linked to the June hack of the fan-token platform Favrr.

Other insights from the leaked device include simple technical searches, such as whether ERC-20 tokens can operate on Solana SOL $204.26 , and queries like identifying top artificial intelligence (AI) developers in Europe.

Recently, Meta deleted over 6.8 million WhatsApp accounts linked to scam groups running crypto fraud schemes. How do these scam groups operate? Read the full story.

Aaron S. Editor-In-Chief
Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.

Loading...
binance
×
Verified

CLAIM $100 BONUS

Changelly Welcome Reward
Rating
5.0