North Korean IT workers used 30+ fake IDs to target crypto companies: report

2025/08/14 16:09

A compromised device from a North Korean IT worker has exposed the inner workings of the team behind the $680,000 Favrr hack and their use of Google tools to target crypto projects.

Summary
  • A compromised device belonging to a North Korean IT worker exposed the inner workings of threat actors.
  • Evidence shows operatives used Google powered tools, AnyDesk, and VPNs to infiltrate crypto firms.

According to on-chain sleuth ZachXBT, the trail began with an unnamed source who gained access to one of the workers’ computers, uncovering screenshots, Google Drive exports, and Chrome profiles that pulled back the curtain on how the operatives planned and carried out their schemes.

Drawing on wallet activity and matching digital fingerprints, ZachXBT verified the source material and tied the group’s cryptocurrency dealings to the June 2025 exploit of the fan-token marketplace Favrr. One wallet address, “0x78e1a,” showed direct links to stolen funds from the incident.

Inside the operation

The compromised device showed that the small team — six members in total — shared at least 31 fake identities. To land blockchain development jobs, they amassed government-issued IDs and phone numbers, even buying LinkedIn and Upwork accounts to complete their cover.

An interview script found on the device showed them boasting of experience at well-known blockchain firms, including Polygon Labs, OpenSea, and Chainlink.

Google tools were central to their organized workflow. The threat actors were found to be using drive spreadsheets to track budgets and schedules, while Google Translate bridged the language gap between Korean and English. 

Among the information pulled from the device was a spreadsheet that showed IT workers were renting computers and paying for VPN access to buy fresh accounts for their operations.

The team also relied on remote access tools such as AnyDesk, allowing them to control client systems without revealing their true locations. VPN logs tied their activity to multiple regions, masking North Korean IP addresses.

Additional findings revealed the group looking up ways to deploy tokens across different blockchains, scouting AI firms in Europe, and mapping out fresh targets in the crypto space.

North Korean threat actors use remote jobs

ZachXBT found the same pattern flagged in multiple cybersecurity reports — North Korean IT workers landing legitimate remote jobs to slip into the crypto sector. By posing as freelance developers, they gain access to code repositories, backend systems, and wallet infrastructure.

One document uncovered on the device was interview notes and preparation materials likely meant to be kept on-screen or nearby during calls with potential employers.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Use XRP to Mine Bitcoin with The ALL4 Mining Cloud Mining Service Provider and Turn Your Holdings into Daily Income

Use XRP to Mine Bitcoin with The ALL4 Mining Cloud Mining Service Provider and Turn Your Holdings into Daily Income

In the rapidly evolving cryptocurrency landscape, savvy investors are no longer simply holding onto their assets – they’re letting them work. A growing number of XRP holders are leveraging ALL4 Mining’s highly efficient computing platform, which remotely powers Bitcoin mining machines without the need for physical hardware. What is Bitcoin Cloud Mining? Bitcoin cloud mining is a method of mining Bitcoin remotely over the internet. Unlike traditional Bitcoin mining, users do not need to purchase and maintain physical mining machines and other related hardware. Instead, they can pay a subscription or lease fee to access the mining resources of a data center. These data centers are often located in locations with lower electricity and maintenance costs, making mining more economical. The basic principle of cloud mining is that users sign a contract with a cloud mining service provider and select a suitable mining package, which typically involves a certain initial fee and a service period. Once the contract is in place, the service provider is responsible for maintaining and operating the mining equipment and distributing the cryptocurrency earned to the user in the agreed-upon proportions. How to Mine Bitcoin on ALL4 Mining? Step 1: Register an Account Create your free account in less than a minute and receive a $15 welcome bonus, which will allow you to earn $0.60 per day in free initial deposits. Step 2: Top up your account: Obtain your cryptocurrency deposit address on the deposit page and complete the transfer (you can participate with as little as $100). Step 3: Choose a Plan Choose from a variety of mining plans to meet your financial goals. Whether you’re looking for short-term gains or long-term returns, ALL4 Mining has something for you. Click to view more online contracts Step 4: Start Earning You earn with no management required. Daily profits will be automatically credited to your account the day after you purchase the contract. When your account reaches $100, you can choose to withdraw it to your crypto wallet or continue purchasing contracts to earn more profits. ALL4 Mining’s Core Advantages Include: Powered by renewable energy: Mines are located in Northern Europe, Canada, Asia, and North America, regions with abundant green energy resources. All operations rely on solar, hydropower, and wind power. Deposits and withdrawals are available in a variety of cryptocurrencies: DOGE, BTC, ETH, SOL, XRP, USDC, LTC, USDT-TRC20, USDT-ERC20, and more. Affiliate program: This affiliate program allows users to earn up to 3% + 1.5% referral rewards and up to $30,000 in bonuses. Compliance and transparency: The company is registered in the UK and operates legally, ensuring transparency and compliance on the platform, protecting user rights. About ALL4 Mining ALL4 Mining is a rapidly growing digital asset mining service provider and a leading global cloud mining service provider. Founded in January 2019 and headquartered in the UK, ALL4 Mining has grown over the years to include over 200 mining farms worldwide, with members in over 200 countries and trusted by over 9 million users worldwide. We believe that everyone should benefit from cloud mining and aim to be a leader in the cloud mining industry. Security and Sustainability Trust and security are paramount in the cryptocurrency mining industry. Our transparent and compliant cloud mining platform works to ensure the safety of every user’s assets. Conclusion As Bitcoin continues to capture the attention of cryptocurrency enthusiasts worldwide, ALL4 Mining offers a unique opportunity to convert this momentum into real daily returns—all powered by sustainable energy and backed by enterprise-grade security. Whether you’re mining Dogecoin, Bitcoin, or XRP, ALL4 Mining makes mining simple, transparent, and efficient. Click to download Google Apps
Share
CryptoNews2025/08/16 13:00