Cointime

Download App
iOS & Android

North Korean hackers used AI-enabled social engineering in Zerion attack

Validated Individual Expert

Crypto wallet Zerion revealed that North Korean-affiliated hackers used AI in a long-term social engineering attack to steal about $100,000 from the company’s hot wallets last week. 

The Zerion team released a post-mortem on Wednesday, where it confirmed that no user funds, Zerion apps or infrastructure were affected and that it had proactively disabled the web app as a precaution. 

While the amount was relatively small in crypto hacking terms, it is another incident of a crypto worker being targeted for an “AI-enabled social engineering attack linked to a DPRK threat actor,” Zerion said.

It is the second attack of this nature this month, following the $280 million exploit of the Drift Protocol, which was the victim of a “structured intelligence operation” by DPRK-affiliated hackers. The human layer, not smart contract bugs, has now become North Korea’s primary point of entry into crypto firms.  

AI is changing the way cyber threats work

Zerion said the attacker gained access to some team members’ logged-in sessions and credentials, as well as private keys to company hot wallets. 

“This incident showed that AI is changing the way cyber threats work,” the company said. 

It confirmed that the attack was similar to those that had been investigated by the Security Alliance (SEAL) last week.

SEAL reported that it had tracked and blocked 164 domains linked to the DPRK group UNC1069 in a two-month window from February to April.

It stated that the group operates “multiweek, low-pressure social engineering campaigns” across Telegram, LinkedIn and Slack. Malicious actors impersonate known contacts or credible brands or leverage access to previously compromised company and individual accounts.

“UNC1069’s social engineering methodology is defined by patience, precision, and the deliberate weaponization of existing trust relationships.”

Google’s cybersecurity unit Mandiant detailed in February the group’s use of fake Zoom meetings and a “known use of AI tools by the threat actor for editing images or videos during the social engineering stage.”

DPRK’s social engineering is evolving

Earlier this month, MetaMask developer and security researcher Taylor Monahan said North Korean IT workers have been embedding themselves in crypto companies and decentralized finance projects for at least seven years.

“The evolution of the DPRK’s social engineering techniques, combined with the increasing availability of AI to refine and perfect these methods, means the threat extends well beyond exchanges,” blockchain security firm Elliptic said in a blog post earlier this year. 

“Individual developers, project contributors, and anyone with access to cryptoasset infrastructure is a potential target.”

  There are two types of DPRK attack vectors, one more sophisticated than the other. Source: ZachXBT
Comments

All Comments

Recommended for you

  • BTC Surpasses $75,000

    Market data shows that BTC has surpassed $75,000, currently priced at $75,003.04, with a 24-hour increase of 0.85%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Drift Secures $147.5 Million in Funding from Tether for User Recovery

    On April 16, Drift announced that the Drift Protocol has received support from Tether and other partners, with Tether contributing $127.5 million and other partners contributing $20 million to assist in user recovery following the attack on April 1. The support plan includes a $100 million revenue-linked credit line, ecosystem grants, and loans to market makers. Drift will establish a dedicated user recovery pool aimed at gradually addressing the $295 million in outstanding user losses as trading revenues increase. Additionally, Drift will issue independent recovery tokens to affected users, which represent a claim to the recovery pool and can be transferred. Drift is currently working on restarting the protocol and has hired Ottersec and Asymmetric for audits, while migrating the settlement layer from USDC to USDT. The previous attack resulted in the theft of approximately $295 million in assets, while the insurance fund's assets remained unaffected.

  • TAO Falls Below $240

    Market data shows that TAO has fallen below $240, currently priced at $239.9, with a 24-hour decline of 3.62%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US Secretary: Military Ready to Resume Operations if Iran Fails to Reach Peace Agreement

    On April 16, US Secretary of Defense Lloyd Austin stated at a Pentagon press conference on Thursday that if Iran does not agree to a peace agreement, US troops stationed in the Middle East are prepared to resume military operations. "Iran, you can choose a prosperous future, a golden bridge, and we hope you do this for the Iranian people," he said. "But if Iran makes the wrong choice, they will face blockades, and their infrastructure, electricity, and energy will suffer bombings." As part of efforts to pressure Tehran to reach an agreement, the US military is implementing a blockade on all vessels attempting to enter or exit Iran.

  • U.S. Launches Operation 'Economic Fury' Against Iran

    On April 16, U.S. Secretary of Defense Lloyd Austin stated at a press conference that the U.S. Treasury Department is launching an operation codenamed 'Economic Fury' to 'maximize economic pressure on Iran.' (CCTV)

  • US Expands Shipping Blockade Against Iran

    According to a report by Reuters on the 16th, the US military announced that it has expanded the blockade on Iranian shipping materials, now including weapons, ammunition, crude oil, refined oil, steel, and aluminum. (Xinhua News Agency)

  • Abraxas Capital Deposits 1,993 Bitcoins Worth $148.32 Million to Kraken

    On April 16, according to monitoring by Lookonchain, Abraxas Capital (Alpha Bitcoin Fund) has just deposited 1,993 bitcoins, valued at $148.32 million, to Kraken. Since March 14, Abraxas Capital (Alpha Bitcoin Fund) has cumulatively deposited 9,582 bitcoins, worth $691 million, to Kraken, and currently holds 20,337 bitcoins, valued at $1.51 billion.

  • National Cyberspace Administration Continues to Address Online Financial Information Chaos

    On April 16, it was reported that the National Cyberspace Administration continues to rectify the chaos surrounding online financial information. (Xinhua News Agency)

  • China Responds to Trump's Sanctions on Countries Purchasing Iranian Oil

    On April 16, Foreign Ministry spokesperson Guo Jiaqin held a regular press conference. A Reuters reporter asked about U.S. President Trump's statement yesterday, in which he expressed confidence that China would not stop buying Iranian oil. He also mentioned that sanctions would be imposed on countries purchasing Iranian oil. Guo Jiaqin stated that China has always opposed illegal unilateral sanctions that lack international legal basis and are not authorized by the United Nations Security Council. (Beijing Daily)

  • Solana Institute-backed super PAC pours $8 million against Sherrod Brown in Ohio race

    Sentinel Action Fund said it will spend $8 million with its sister advocacy group to back Republican Senator Jon Husted against Sherrod Brown in the upcoming race.