North Korean hackers are targeting cryptocurrency firms and their staff with sophisticated social engineering assaults to steal their money, according to the FBI.
The FBI says their social engineering is focused and hard to detect, even for cybersecurity experts.
Over the previous few months, North Korean threat actors have been researching possible targets, concentrating on bitcoin ETF and other financial instrument holders. They may be prepared to assault bitcoin ETF and other asset businesses with this degree of pre-operational staging.
Law enforcement cautioned that North Korean hacker gangs may target firms that handle large amounts of cryptocurrencies to access networks and steal cash.
The FBI notes that these state-sponsored organizations carefully prepare their social engineering efforts, starting with selecting DeFi and bitcoin firms to target. They then socially engineer their workers with offers of new jobs or investments, using comprehensive personal information to gain credibility and attractiveness.
"The actors usually communicate with victims in fluent or nearly fluent English and are well versed in the technical aspects of the cryptocurrency field," the FBI says.
"North Korean cybercriminals mimic many people, including direct and indirect connections. General recruiters on professional networking sites or tech celebrities may be impersonated."
The attackers use stolen photos and well designed websites to make their scams appear real. They are well-versed in bitcoin technology.
The FBI also listed symptoms of North Korean social engineering operations and suggested practices for bitcoin firms and their staff to reduce the danger of compromise.
The FBI has warned about fraudsters acting as crypto exchange personnel and hackers posing as legal companies providing bitcoin recovery services since the start of the year.
It also advised about fraudulent remote work advertising designed to steal cryptocurrencies and unlicensed cryptocurrency transfer firms that might lose money if law enforcement shuts them down.
In December, Recorded Future researchers reported that North Korean-backed state hacking outfits including Kimsuky, Lazarus Group, Andariel, and others had stolen $3 billion in cryptocurrencies since 2017.
"In 2022 alone, North Korean threat actors were accused of stealing $1.7 billion in cryptocurrency, equivalent to 5% of the country's economy or 45% of its military budget," a report added.
In 2017, North Korean hackers stole $82.7 million from South Korean exchanges Bithumb, Youbit, and Yapizon. They have since committed many other crypto heists, including those against Harmony blockchain bridge ($100 million), Nomad bridge ($190 million), Qubit Finance bridge ($80 million), Atomic Wallet ($35 million), AlphaPo ($60 million in two attacks), and CoinsPaid ($37 million).