Cointime

Download App
iOS & Android

North Korea tech workers found among staff at UK blockchain projects

Fraudulent tech workers with ties to North Korea are expanding their infiltration operations to blockchain firms outside the US after increased scrutiny from authorities, with some having worked their way into UK crypto projects, Google says.

Google Threat Intelligence Group (GTIG) adviser Jamie Collier said in an April 2 report that while the US is still a key target, increased awareness and right-to-work verification challenges have forced North Korean IT workers to find roles at non-US companies.

“In response to heightened awareness of the threat within the United States, they’ve established a global ecosystem of fraudulent personas to enhance operational agility,” Collier said. 

“Coupled with the discovery of facilitators in the UK, this suggests the rapid formation of a global infrastructure and support network that empowers their continued operations,” he added. 

The North Korea-linked workers are infiltrating projects spanning traditional web development and advanced blockchain applications, such as projects involving Solana and Anchor smart contract development, according to Collier. 

Another project building a blockchain job marketplace and an artificial intelligence web application leveraging blockchain technologies was also found to have North Korean workers. 

“These individuals pose as legitimate remote workers to infiltrate companies and generate revenue for the regime,” Collier said. 

“This places organizations that hire DPRK [Democratic People's Republic of Korea] IT workers at risk of espionage, data theft, and disruption.”

North Korea looking to Europe for tech jobs

Along with the UK, Collier says the GTIG identified a notable focus on Europe, with one worker using at least 12 personas across Europe and others using resumes listing degrees from Belgrade University in Serbia and residences in Slovakia. 

Separate GTIG investigations found personas seeking employment in Germany and Portugal, login credentials for user accounts of European job websites, instructions for navigating European job sites, and a broker specializing in false passports.

At the same time, since late October, the North Korean workers have increased the volume of extortion attempts and gone after larger organizations, which the GTIG speculates is the workers feeling pressure to maintain revenue streams amid a crackdown in the US. 

“In these incidents, recently fired IT workers threatened to release their former employers’ sensitive data or to provide it to a competitor. This data included proprietary data and source code for internal projects,” Collier said. 

In January, the US Justice Department indicted two North Korean nationals for their involvement in a fraudulent IT work scheme involving at least 64 US companies from April 2018 to August 2024.

The US Treasury Department’s Office of Foreign Assets Control also sanctioned companies it accused of being fronts for North Korea that generated revenue via remote IT work schemes.

Crypto founders have also been reporting an increase in activity from North Korean hackers, with at least three founders reporting on March 13 that they foiled attempts to steal sensitive data through fake Zoom calls.

  In August, blockchain investigator ZachXBT claimed to have uncovered a sophisticated network of North Korean developers earning $500,000 a month working for “established” crypto projects.  

Comments

All Comments

Recommended for you

  • Ghana passes law legalizing the use of cryptocurrency

    according to Bloomberg, the Ghanaian Parliament has approved a cryptocurrency legalization bill aimed at addressing the expanding use of cryptocurrencies in the country but the lack of regulation. According to Johnson Asiamah, Governor of the Bank of Ghana, the newly passed Virtual Asset Service Providers Act will facilitate the licensing of crypto platforms and the regulation of related activities.

  • CryptoQuant: Bitcoin network activity cools, market shows clear bearish signs.

    CryptoQuant published an analysis stating that the Bitcoin market continues to be in a bear market state, with multiple network indicators showing a significant cooling of activity. Data shows that the 30-day moving average of Bitcoin is below the 365-day moving average (-0.52%), and the bull-bear cycle indicator confirms the current bear market pattern. The number of network transactions has dropped from about 460,000 to about 438,000, fees have decreased from $233,000 to $230,000, and highly active addresses have reduced from 43.3K to 41.5K, all indicating reduced speculative activity and that the market is in a defensive phase.

  • ETH falls below $3,000

    the market shows that ETH has fallen below $3000, currently at $2999.5, with a 24-hour increase of 0.86%. The market is highly volatile, please manage your risks accordingly.

  • BTC breaks through $89,000

    market shows BTC breaking through $89,000, currently at $89,014.5, with a 24-hour increase of 0.85%. The market is highly volatile, please manage your risk accordingly.

  • F2Pool co-founder: Last year, 500 bitcoins were transferred in to confirm whether the private key had been leaked; hackers took 490 bitcoins.

    regarding the community's heated discussion about the 50 million USDT phishing attack, F2Pool co-founder Wang Chun tweeted, "Last year, I suspected that my private key was leaked. To confirm whether the address was really hacked, I transferred 500 bitcoins to that address. To my surprise, the hacker 'generously' only took 490 bitcoins, leaving me 10 bitcoins, enough for me to make a living."

  • BTC falls below $88,000

    market shows BTC fell below $88,000, currently at $87,991.97, with a 24-hour decline of 0.08%. The market is highly volatile, please manage your risk accordingly.

  • US lawmakers draft new bill to exempt capital gains tax on stablecoin transactions under $200.

     U.S. representatives are drafting a cryptocurrency tax bill called the Digital Asset PARITY Act, which will exempt capital gains tax on stablecoin transactions under $200, and staking and mining rewards will also have the option for a five-year tax deferral.

  • Tether CEO posts job openings, sparking speculation that a mobile encrypted wallet is on the horizon.

    Tether CEO Paolo Ardoino posted on the X platform stating that Tether has started recruiting a senior software engineer who will be responsible for Tether's mobile crypto wallet-related products, which will be supported by artificial intelligence, Wallet Development Kit (WDK), and QVAC technology. Later, Paolo Ardoino also posted a suspected wallet product screenshot in another tweet, which shows "Own your Money".

  • Bloomberg analysts: Among the top 25 US equity ETFs with the highest annual inflows, BlackRock IBIT is the only ETF with negative returns.

    Eric Balchunas, a senior ETF analyst at Bloomberg, posted the annual top 25 U.S. stock ETFs by fund inflows on the X platform. Among them, BlackRock's Bitcoin exchange-traded fund IBIT is the only ETF with a negative return, with an annual return rate of -9.59%. It is worth noting that despite the negative return, IBIT's annual fund inflow still ranks sixth, even surpassing the GLD ETF with a 64% return. In the long run, this is a very good sign, as it received over $25 billion in fund inflows during the bear market phase, indicating greater potential once the market turns bullish.