Analysis: North Korean hackers used inducement to run malicious programs to hack into the system and have stolen $1.6 billion in cryptocurrencies this year
TechFlame
2025-08-05 01:14
TechFlame2025-08-05 01:14
English
On August 5, according to research by Google Cloud and cybersecurity company Wiz, North Korean hacker groups are infiltrating cloud systems through false IT job offers, and it is estimated that they have stolen $1.6 billion worth of cryptocurrencies in 2025. Research shows that the hacker team codenamed UNC4899 (also known as TraderTraitor, Jade Sleet, or Slow Pisces) used social media to impersonate recruiters to trick target company employees into running malicious programs, successfully hacking into Google Cloud and AWS systems and hijacking cryptocurrency trading hosts. Wiz said that TraderTraitor represents some type of threat activity rather than a specific group. North Korea-supported entities Lazarus Group, APT38, Blue Noroff, and Stardust Chollima are all behind typical TraderTraitor attacks.
This attack model has continued to evolve since 2020: JavaScript was used to build malicious cryptographic applications in the early days, open source code exploits were introduced in 2023, and attacks focused on exchange cloud infrastructure in 2024, including an intrusion incident that caused a loss of US$305 million in Japanese DMM Bitcoin. Experts pointed out that North Korean hackers were the first to use AI technology to generate phishing emails and malicious scripts, and their attack team may have reached several thousand people.