BTC $77,350.64 +0.26%
ETH $2,513.98 -0.37%
BNB $722.08 -0.61%
XRP $1.36 -0.32%
SOL $101.40 +0.03%
TRX $0.3413 +0.43%
DOGE $0.0843 -0.54%
ADA $0.2088 +0.67%
BCH $224.89 -0.36%
LINK $11.45 -0.41%
HYPE $78.83 -1.00%
AAVE $126.82 +0.88%
SUI $0.7209 -0.37%
XLM $0.1806 +0.38%
ZEC $1,107.01 -1.13%
AAPL $330.73 -0.71%
AMZN $254.47 -0.88%
GOOGL $338.28 -0.81%
MSFT $491.99 -0.61%
META $644.78 -0.56%
NVDA $215.67 -1.20%
TSLA $362.73 -1.24%
SNDK $1,574.96 -3.13%
INTC $99.25 -2.75%
SPCX $149.27 -0.52%
MU $939.46 -2.92%
AMD $502.40 -2.63%
BTC $77,350.64 +0.26%
ETH $2,513.98 -0.37%
BNB $722.08 -0.61%
XRP $1.36 -0.32%
SOL $101.40 +0.03%
TRX $0.3413 +0.43%
DOGE $0.0843 -0.54%
ADA $0.2088 +0.67%
BCH $224.89 -0.36%
LINK $11.45 -0.41%
HYPE $78.83 -1.00%
AAVE $126.82 +0.88%
SUI $0.7209 -0.37%
XLM $0.1806 +0.38%
ZEC $1,107.01 -1.13%
AAPL $330.73 -0.71%
AMZN $254.47 -0.88%
GOOGL $338.28 -0.81%
MSFT $491.99 -0.61%
META $644.78 -0.56%
NVDA $215.67 -1.20%
TSLA $362.73 -1.24%
SNDK $1,574.96 -3.13%
INTC $99.25 -2.75%
SPCX $149.27 -0.52%
MU $939.46 -2.92%
AMD $502.40 -2.63%

crowdstrike

All
Article
Flash

first_img North Korea uses IT employees from third countries to infiltrate American companies, paying interview assistants with cryptocurrency

According to NBC, North Korea is utilizing remote IT workers from third countries such as Iran and Lebanon to assist in infiltrating American companies and obtaining funds to finance its weapons programs. Alerts issued by the U.S. and several foreign agencies in July indicated that North Korean IT workers "seek to sign contracts with the intention of remitting salaries back to relevant North Korean agencies," while also posing internal threats to companies, involving data leaks, cryptocurrency theft, and sensitive information theft.As governments like the United States increase countermeasures, North Korea is increasingly leveraging third-country IT workers to secure job interviews, and after obtaining work contracts, the relevant positions are typically taken over by North Korean agents. Reports indicate that these foreign IT workers are scouted on LinkedIn, with some earning about $500 per month in cryptocurrency to work part-time as "interview assistants."Cointelegraph reported in May, citing data from cybersecurity company CrowdStrike, that state-affiliated North Korean hackers and threat actors caused cryptocurrency losses exceeding $2 billion in 2025, a 51% increase year-on-year. The Bank of Korea estimates that despite facing global sanctions, North Korea's GDP will still grow by 3.5% in 2025.

first_img The U.S. Department of Justice and CrowdStrike teamed up to dismantle the Sality botnet, which had been operating for over 20 years

According to Decrypt, CrowdStrike and the U.S. Department of Justice announced on Tuesday that they have dismantled the Sality peer-to-peer botnet, which has been active since 2003.This botnet primarily hijacked cryptocurrency payments through the EggJagger malware over the past eight years, which monitored the cryptocurrency wallet addresses in victims' clipboards and replaced them with the operator's own address, causing victims to send funds to strangers.CrowdStrike estimates that the operator has stolen at least 12.1 million rubles (approximately $150,000) solely through the EggJagger payload. Most of the stolen cryptocurrency has not been spent, and CrowdStrike assesses that these unspent assets were worth about 147 million rubles (nominally around $1.35 million) at their peak in January 2025. The reason Sality has survived to this day is that it does not have a central server that can be seized; infected machines communicate directly with each other.This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, and police from multiple European countries also seized other domains.CrowdStrike isolated more than 15,000 infected machines to its controlled honeypot by exploiting its architectural vulnerabilities. The operator has been tracked as SALTY SPIDER, which launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.
app_icon
ChainCatcher Building the Web3 world with innovations.