ZachXBT: North Korea's IT team has over 30 false identifications involved in a $680,000 attack incident.

CoinVoice has learned that, according to ZachXBT, a source has revealed that an individual has hacked into the devices of North Korean IT personnel and discovered that a small team obtained developer positions through over 30 fake identifications, used government IDs to purchase Upwork and LinkedIn accounts, and conducted work via AnyDesk. The relevant data includes Google Drive exports, Chrome profiles, and screenshots.

The wallet address 0x78e1 is closely related to the $680,000 attack on the Favrr platform in June 2025, with more North Korean IT personnel also identified. The team utilized Google products to arrange tasks and purchased SSNs, AI subscriptions, and VPNs, among others. Some browsing records show frequent use of Google Translate to translate Korean, with the IP address being in Russia. The negligence of recruiters and the lack of collaboration between services have become the main challenges in combating such activities.

IP1.18%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)