DeFi Daily News
Friday, October 17, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title North Korean IT Workers Infiltrated European Solana-Based Projects: Google – Decrypt

Vismaya V by Vismaya V
April 2, 2025
in Web 3
0 0
0
rewrite this title North Korean IT Workers Infiltrated European Solana-Based Projects: Google – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

North Korean cyber operatives have expanded their reach beyond U.S. firms to target blockchain startups in the EU and UK, posing as remote developers and leaving a trail of compromised data and extortion attempts.

In a report released on Tuesday, Google’s Threat Intelligence Group (GTIG) revealed that IT workers linked to the Democratic People’s Republic of Korea (DPRK) have scaled up operations outside the U.S., embedding themselves in crypto projects across the UK, Germany, Portugal, and Serbia.

❗️North Korean IT Workers: A Growing Threat!

GTIG has seen increased DPRK IT worker ops in Europe, expanding beyond the U.S. They pose as remote workers, putting orgs at risk of espionage, data theft, and disruption.

Learn more: https://t.co/JaHgl3sduj pic.twitter.com/7oOW1WguoJ

— Google Cloud Security (@GoogleCloudSec) April 1, 2025

Compromised projects include blockchain marketplaces, AI web apps, and the development of Solana and Anchor/Rust smart contracts.

One case involved building a Nodexa token hosting platform using Next.js and CosmosSDK, while others included a blockchain job marketplace built using the MERN stack and Solana, and the development of AI-enhanced blockchain tools using Electron and Tailwind CSS.

“In response to heightened awareness of the threat within the United States, they’ve established a global ecosystem of fraudulent personas to enhance operational agility,” said GTIG adviser Jamie Collier in the report.

Some workers operated under 12 fake identities at once, using degrees from Belgrade University, false residency documents from Slovakia, and guidance for navigating European job platforms, the report noted.

Collier said that facilitators based in the UK and U.S. helped these actors bypass ID checks and receive payments via TransferWise, Payoneer, and crypto, effectively hiding the source of funds flowing back to the North Korean regime.

GTIG reports the workers are generating revenue for the North Korean regime, which U.S., Japanese, and South Korean envoys have previously accused of using overseas IT specialists, including those engaged in malicious cyber activity, to help fund its sanctioned weapons programs.

“This places organizations that hire DPRK IT workers at risk of espionage, data theft, and disruption,” Collier warned.

Extortion threats

Since October 2024, GTIG observed a surge in extortion threats as laid-off DPRK developers have begun blackmailing former employers with threats to leak source code and proprietary files.

This uptick in aggression, GTIG noted, coincides with “heightened United States law enforcement actions against DPRK IT workers, including disruptions and indictments.”

Last December, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two Chinese nationals for laundering digital assets to finance North Korea’s government, using a UAE-based front company tied to the regime in Pyongyang.

Then, in January, the Justice Department indicted two North Korean nationals for operating a fraudulent IT work scheme that infiltrated at least 64 U.S. companies between 2018 and 2024.

Beyond Lazarus Group

In March, Paradigm security researcher Samczsun warned that the DPRK’s cyber strategy goes far beyond the State-backed Lazarus Group, which has been linked to some of the largest crypto hacks in history.

“DPRK hackers are an ever-growing threat against our industry,” Samczsun wrote, outlining a web of subgroups like TraderTraitor and AppleJeus, which specialize in social engineering, fake job offers, and supply chain attacks.

In February, hackers tied to Lazarus stole $1.4 billion from crypto exchange Bybit, with the funds later funneled through coin mixers and  DEX.

As the crypto industry leans heavily on remote talent and bring-your-own-device (BYOD) environments, GTIG warned that many startups lack proper monitoring tools to detect such threats.

And that, Collier said, is exactly the point—with North Korea exploiting, “the rapid formation of a global infrastructure and support network that empowers their continued operations.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: DecryptEuropeanGoogleInfiltratedKoreanNorthprojectsrewriteSolanaBasedtitleworkers
ShareTweetShare
Previous Post

Trump again to visit Saudi Arabia in first foreign trip of term

Next Post

rewrite this title and make it good for SEO Bybit to Close NFT Marketplace Amid 95% Industry Volume Decline

Next Post
rewrite this title and make it good for SEO Bybit to Close NFT Marketplace Amid 95% Industry Volume Decline

rewrite this title and make it good for SEO Bybit to Close NFT Marketplace Amid 95% Industry Volume Decline

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
Why Outlet Malls Are Struggling In The U.S.

Why Outlet Malls Are Struggling In The U.S.

July 16, 2024
rewrite this title Repair from Millions of Kilometers Away: How NASA Keeps the Mars Rovers Alive

rewrite this title Repair from Millions of Kilometers Away: How NASA Keeps the Mars Rovers Alive

September 29, 2025
Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

July 31, 2024
rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for .7 billion, in Buffett’s biggest deal in three years

rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for $9.7 billion, in Buffett’s biggest deal in three years

October 2, 2025
Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

August 14, 2024
rewrite this title Während BlackRock Geldanlagen tokenisiert, wird PepeNode das Mining revolutionieren! | Bitcoinist.com

rewrite this title Während BlackRock Geldanlagen tokenisiert, wird PepeNode das Mining revolutionieren! | Bitcoinist.com

October 14, 2025
rewrite this title Reddit expands its AI-powered search to five new languages | TechCrunch

rewrite this title Reddit expands its AI-powered search to five new languages | TechCrunch

October 17, 2025
rewrite this title Did Ace Frehley Have Children? Meet the Late KISS Guitarist’s Daughter Monique

rewrite this title Did Ace Frehley Have Children? Meet the Late KISS Guitarist’s Daughter Monique

October 16, 2025
rewrite this title Bitcoin Buy Signal: Why The 200-Week Moving Average Has Been A Flawless Entry Point

rewrite this title Bitcoin Buy Signal: Why The 200-Week Moving Average Has Been A Flawless Entry Point

October 16, 2025
rewrite this title Insider questions Kyler Murray’s future with Cardinals

rewrite this title Insider questions Kyler Murray’s future with Cardinals

October 16, 2025
rewrite this title Nasdaq-Listed Zeta Network Raises 1M via Bitcoin-Backed Private Placement – Decrypt

rewrite this title Nasdaq-Listed Zeta Network Raises $231M via Bitcoin-Backed Private Placement – Decrypt

October 16, 2025
rewrite this title with good SEO The XRP Price Roadmap To : How An Over 50% Bounce Could Materialize

rewrite this title with good SEO The XRP Price Roadmap To $8: How An Over 50% Bounce Could Materialize

October 16, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.