2020 - 2021 Best Cryptocurrency News Investment Guide

North Korean hackers set up 3 shell companies to scam crypto devs
2025-04-25 17:00:19 Primitive Reading

 

A subgroup of the North Korea-linked hacker organization Lazarus set up three shell companies, two in the United States, to deliver malware to unsuspecting users.

The three sham crypto consulting firms — BlockNovas, Angeloper Agency and SoftGlide — are being used by the North Korean hacker group Contagious Interview to distribute malware through fake job interviews, Silent Push threat analysts said in an April 24 report.

Silent Push senior threat analyst Zach Edwards said in an April 24 statement to X that two shell companies are registered as legitimate businesses in the US.

“These websites and a huge network of accounts on hiring / recruiting websites are being used to trick people into applying for jobs,” he said.

“During the job application process an error message is displayed as someone tries to record an introduction video. The solution is an easy click fix copy and paste trick, which leads to malware if the unsuspecting developer completes the process.”

Three strains of malware — BeaverTail, InvisibleFerret and Otter Cookie — are being used according to Silent Push.

BeaverTail is malware primarily designed for information theft and to load further stages of malware. OtterCookie and InvisibleFerret mainly target sensitive information, including crypto wallet keys and clipboard data.

Silent Push analysts said in the report that hackers use GitHub job listing's and freelancer websites to look for victims, among others.

AI used to create fake employees 

The ruse also involves the hackers using AI-generated images to create profiles of employees for the three front crypto companies and stealing images of real people.

“There are numerous fake employees and stolen images from real people being used across this network. We’ve documented some of the obvious fakes and stolen images, but it’s very important to appreciate that the impersonation efforts from this campaign are different,” Edwards said.

“In one of the examples, the threat actors took a real photo from a real person, and then appeared to have run it through an AI image modifier tool to create a subtly different version of that same image.”

This malware campaign has been ongoing since 2024. Edwards says there are known public victims.

Disclaimer: This specification is preliminary and is subject to change at any time without notice. MYTOKEN assumes no responsibility for any errors contained herein.

Recommended reading
Saylor holding 10M BTC won’t ‘threaten the protocol,’ says author

10-22     admin     18671 Reading

Fed Joins OCC, FDIC in Withdrawing Crypto Warnings for U.S. Banks

10-22     admin     12664 Reading

ZKSync Hacker Returns $5M in Stolen Tokens After Accepting 10% Bounty

10-22     admin     13578 Reading

Bitcoin’s April Rally Driven by Institutions, While Retail Flees ETFs: Coinbase Exec

10-22     admin     14706 Reading

Strike’s Mallers to head firm seeking superior Bitcoin play to MSTR

10-22     admin     18913 Reading

Institutions break up with Ethereum but keep ETH on the hook

10-22     admin     16877 Reading

DeFi platform KiloEx to compensate users impacted by $7.5M hack

10-22     admin     18029 Reading

TRUMP Coin Jumps 70% on President's Dinner Event for Top Token Holders

10-22     admin     11029 Reading

U.S. Derivatives Watchdog Weighs 24/7 Action With Crypto Oversight on Horizon

10-22     admin     9940 Reading

ECB flags risk of financial contagion from US crypto push

10-22     admin     15301 Reading

WazirX to Get Day in Court Next Month, With Payouts After 10 Days If Recovery Plan is Approved

10-22     admin     13192 Reading

Grayscale CEO Peter Mintzberg reveals plans for crypto giant’s next act

10-22     admin     11016 Reading

Former SEC Chair Jay Clayton sworn in as interim US attorney for Manhattan

10-22     admin     7895 Reading

Bitcoin analysts target $95K as Trump’s trade war cools — Do BTC futures agree?

10-22     admin     18327 Reading

Yuga Labs Demands $400K in Influencer’s Crypto Wallets Over NFT Lawsuit

10-22     admin     16155 Reading