Lazarus Group Targeting LinkedIn Users As Part Of North Korea Crypto Hacking Scheme

crypto scam Lazarus Group North Korea
Last updated:
Author
Author
Julia Smith
About Author

Julia is an experienced editor with a passion for covering a wide variety of beats. She loves all things politics and regularly covers regulatory updates on emerging technology here for Crypto News.

Last updated:
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

North Korea’s state-sponsored hacking collective Lazarus group is reportedly targeting LinkedIn users in the digital asset industry as part of its latest crypto hacking malware attempt, blockchain security firm SlowMist alleged on April 24.“The Lazarus Group is currently contacting cryptocurrency industry targets through LinkedIn and stealing employee privileges or assets through malware,” SlowMist posted to its X account

North Korean Crypto Hacking Group Targeting LinkedIn Users

The blockchain security company alleged that Lazarus Group members were creating fake profiles on the networking site and reaching out to human resources personnel and hiring managers in various blockchain-related organizations. 

From there, the North Korean hackers send a link with code in an attempt to show off their coding abilities. In reality, the cryptography contains dangerous malware to exploit the victim’s personal data.

“Initial declarations and dependency loading scripts throw errors immediately when they start, probably to confuse analyzers or automated tools,” SlowMist stated. “Several Node.js modules are imported, and environment variables and function definitions define the operating system’s hostname, platform type, home directory, and temporary directories.

A periodic function, aptly named “stealEverything” then “attempts to steal as much data as possible from the user’s device and upload it to a server controlled by the attacker.”

Lazarus Group’s Ties To North Korea’s WMD Program

A report from a U.N. panel of experts published last month revealed that an estimated 40% of North Korea’s weapons of mass destruction (WMD) were funded through “illicit cyber means.”Lazarus Group has stolen over $3 billion worth of digital assets globally to date.A recent TRM Labs report found that the authoritarian country stole over $600 million in 2023 alone.Security officials from the U.S. and its allies believe the country’s state-sponsored malware initiatives may threaten national security.In December, U.S. advisor of National Security, Jake Sullivan, held a meeting with diplomatic counterparts from South Korea and Japan in which they discussed North Korea’s WMD program.Last year, the U.S. sanctioned crypto mixer Sinbad, a “key money-laundering tool” for the regime’s digital asset exploitation efforts.“The Treasury Department and its U.S. government partners stand ready to deploy all tools at their disposal to prevent virtual currency mixers, like Sinbad, from facilitating illicit activities,” Deputy Secretary of the Treasury Wally Adeyemo said following the enforcement action. “While we encourage responsible innovation in the digital asset ecosystem, we will not hesitate to take action against illicit actors.”It’s unclear whether the Lazarus Group will face any repercussions over its latest crypto malware scheme.

More Articles

DeFi News
BlackRock Expands BUIDL Fund to Include Solana (SOL)
Hassan Shittu
Hassan Shittu
2025-03-25 21:52:27
Blockchain News
The Digital Chamber Releases Blockchain Policy Framework In Latest Initiative
Julia Smith
Julia Smith
2025-03-25 21:49:50
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors