Cointime

Download App
iOS & Android

North Korean hackers used AI-enabled social engineering in Zerion attack

Validated Individual Expert

Crypto wallet Zerion revealed that North Korean-affiliated hackers used AI in a long-term social engineering attack to steal about $100,000 from the company’s hot wallets last week. 

The Zerion team released a post-mortem on Wednesday, where it confirmed that no user funds, Zerion apps or infrastructure were affected and that it had proactively disabled the web app as a precaution. 

While the amount was relatively small in crypto hacking terms, it is another incident of a crypto worker being targeted for an “AI-enabled social engineering attack linked to a DPRK threat actor,” Zerion said.

It is the second attack of this nature this month, following the $280 million exploit of the Drift Protocol, which was the victim of a “structured intelligence operation” by DPRK-affiliated hackers. The human layer, not smart contract bugs, has now become North Korea’s primary point of entry into crypto firms.  

AI is changing the way cyber threats work

Zerion said the attacker gained access to some team members’ logged-in sessions and credentials, as well as private keys to company hot wallets. 

“This incident showed that AI is changing the way cyber threats work,” the company said. 

It confirmed that the attack was similar to those that had been investigated by the Security Alliance (SEAL) last week.

SEAL reported that it had tracked and blocked 164 domains linked to the DPRK group UNC1069 in a two-month window from February to April.

It stated that the group operates “multiweek, low-pressure social engineering campaigns” across Telegram, LinkedIn and Slack. Malicious actors impersonate known contacts or credible brands or leverage access to previously compromised company and individual accounts.

“UNC1069’s social engineering methodology is defined by patience, precision, and the deliberate weaponization of existing trust relationships.”

Google’s cybersecurity unit Mandiant detailed in February the group’s use of fake Zoom meetings and a “known use of AI tools by the threat actor for editing images or videos during the social engineering stage.”

DPRK’s social engineering is evolving

Earlier this month, MetaMask developer and security researcher Taylor Monahan said North Korean IT workers have been embedding themselves in crypto companies and decentralized finance projects for at least seven years.

“The evolution of the DPRK’s social engineering techniques, combined with the increasing availability of AI to refine and perfect these methods, means the threat extends well beyond exchanges,” blockchain security firm Elliptic said in a blog post earlier this year. 

“Individual developers, project contributors, and anyone with access to cryptoasset infrastructure is a potential target.”

  There are two types of DPRK attack vectors, one more sophisticated than the other. Source: ZachXBT
Comments

All Comments

Recommended for you

  • BTC Surpasses $74,000

    Market data shows that BTC has surpassed $74,000, currently priced at $74,005.64, with a 24-hour decline of 0.54%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Paxos Labs to use $12M raise toward yield, lending, issuance tools

    Backed by Blockchain Capital, the Amplify suite aims to enable platforms to generate yield and offer lending using customer-held digital assets.

  • US Spot Ethereum ETF Sees Net Inflow of $53.03 Million Yesterday

    On April 15, according to monitoring by Trader T, the US spot Ethereum ETF experienced a net inflow of $53.03 million yesterday.

  • US Spot Bitcoin ETF Sees Net Inflow of $411.49 Million Yesterday

    On April 15, according to monitoring by Trader T, the US spot Bitcoin ETF saw a net inflow of $411.49 million yesterday.

  • Bessent: Tariff Levels May Be Restored Before Early July

    On April 15, U.S. Treasury Secretary Bessent stated that the tariff levels imposed by Trump may be restored to their pre-Supreme Court ruling levels before early July. After the Supreme Court ruled that Trump's use of emergency powers to impose early tariffs was unconstitutional, Bessent is seeking to rebuild his 'tariff wall' using different authorizations, such as Section 301 investigations. Bessent mentioned that while it is difficult to predict when the consequences of the Iraq War will 'spill over' into the U.S. economy, the current economic conditions remain strong. He believes that the U.S. growth rate this year could easily exceed 3% or even 3.5%. He also added that the continuous decline in core inflation, excluding volatile energy and food prices, is a positive sign. Bessent stated, 'I believe the Federal Reserve has consistently misjudged the inflation issue; core inflation is declining. If they want to wait for clearer data before taking action, I understand, but that would mean interest rates should be lowered more.' (Jin Shi)

  • BTC Falls Below $74,000

    Market data shows that BTC has fallen below $74,000, currently priced at $73,999.01, with a 24-hour decline of 0.15%. The market is experiencing significant volatility; please ensure proper risk management.

  • Goldman Sachs Plans to Launch 'Bitcoin Premium Yield ETF'

    On April 14, according to market news, Goldman Sachs has submitted an application to launch the 'Bitcoin Premium Yield ETF'.

  • ETH Breaks $2400

    Market data shows that ETH has surpassed $2400, currently priced at $2404.84, with a 24-hour increase of 8.75%. The market is highly volatile, so please ensure proper risk management.

  • BTC Surpasses $76,000

    Market data shows that BTC has surpassed $76,000, currently priced at $76,004.75, with a 24-hour increase of 6.03%. The market is experiencing significant volatility, so please ensure proper risk management.