Kraken Discovers North Korean Hacker Attempting Infiltration as US FinCEN Proposes Ban on Huione Group
By: bitcoin ethereum news|2025/05/02 23:45:01
0
Share
Kraken uncovered a North Korean hacker posing as a job candidate, advancing through hiring to gather intel on infiltration tactics. The hacker used fake identities and suspicious technical setups, revealing ties to state-sponsored cybercrime. The US Financial Crimes Enforcement Network proposed a ban on Huione Group for facilitating North Korean cybercriminals in laundering illicit funds. Kraken’s discovery of a North Korean hacker during recruitment raises significant concerns about cybersecurity in the crypto industry. How a North Korean Hacker Tried to Infiltrate Kraken Kraken detailed the incident in a recent blog post on May 1. The hacker applied for an engineering role at the exchange, initially appearing as a legitimate candidate, allegedly named Steven Smith. However, several red flags emerged during the hiring process. “What started as a routine hiring process for an engineering role quickly turned into an intelligence gathering operation,” Kraken noted. This systematic approach allowed teams to learn more about the hacker’s tactics at every stage. The candidate used various names during interviews and seemed to switch voices, suggesting coaching. Their application was linked to email addresses associated with North Korean hackers. Additionally, an Open-Source Intelligence (OSINT) investigation revealed the candidate’s ties to a network of fake identities. “This meant that our team had uncovered a hacking operation where one individual had established multiple identities to apply for roles in the crypto space and beyond,” the blog read. Evidence showed that these identities had previously been hired by numerous companies, with some flagged as foreign agents on the sanctions list. Technical inconsistencies in their setup, like using remote, colocated Mac desktops accessed via a VPN, indicated an infiltration attempt. This information underscored that the candidate was likely a state-sponsored hacker. In a final interview, Kraken’s Chief Security Officer, Nick Percoco, confirmed the company’s suspicions. The candidate’s inability to verify their location or answer questions regarding their citizenship revealed them as an impostor. “Their job is to start employment to steal intellectual property, steal money from those companies, take home a paycheck, and do it in a widespread way,” Percoco elaborated during an interview with CBS. FinCEN Proposes Ban on Huione Group Over North Korean Ties Meanwhile, the US Financial Crimes Enforcement Network (FinCEN) has proposed banning the Cambodia-based Huione Group from the US financial system due to its suspected facilitation of North Korean cybercriminals involved in major cyber heists. “Huione Group has established itself as the marketplace of choice for malicious cyber actors, including DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans,” stated Secretary of the Treasury Scott Bessent. FinCEN accused Huione of laundering over $4 billion in illicit funds between August 2021 and January 2025. The department noted that Huione’s operations, including Huione Pay and Huione Crypto, serve as preferred platforms for criminals engaging in cryptocurrency-related fraud and transactions. “Today’s proposed action will sever Huione Group’s access to correspondent banking, degrading these groups’ ability to launder their ill-gotten gains,” Bessent added, emphasizing the Treasury’s commitment to disrupting cybercriminal revenue streams. These incidents underscore a disturbing pattern of North Korean cyberattacks targeted at the cryptocurrency sector, with hackers stealing over $659 million from crypto firms in 2024 alone. In a joint statement from the United States, Japan, and South Korea, it was reported that North Korean hackers employed social engineering and malware tactics to infiltrate targets. Crucially, previous reports have traced the activities of the notorious Lazarus Group to high-profile thefts at platforms such as Bybit and Upbit. Moreover, these hacker groups were implicated in the Radiant Capital hack and the DMM Bitcoin exploit. On-chain investigator ZachXBT recently uncovered significant North Korean impact on decentralized finance (DeFi) protocols, with some protocols relying nearly entirely on transaction volumes associated with the Democratic People’s Republic of Korea (DPRK). Conclusion This alarming situation highlights the evolving challenges that the cryptocurrency industry faces with sophisticated cyber threats. Readers need to remain vigilant, ensuring robust security measures are crucial for any involved in the crypto space. Source: https://en.coinotag.com/kraken-discovers-north-korean-hacker-attempting-infiltration-as-us-fincen-proposes-ban-on-huione-group/
You may also like

Once you're over 25, you're already too old to be playing with meme coins.
Pump.fun, the world's largest 24-hour online esports platform

Four New Frontlines Post Ceasefire | Rewire News Daily Brief
Rate Cut Window Pushed Beyond Year End

Holmez accepts Bitcoin for toll payment, how much can Iran earn?
When you stretch the numbers and do the math, the answer turns out to be unexpectedly small

When No One on the Team Wants to Sell: The Valuation Game at Anthropic Enters the “Seller Disappearance” Stage
Anthropic's stock, priced at $350 billion, some want to buy but can't buy enough, some can sell but unwilling to sell.

Anthropic's new product, powerful enough to make the AI Agent Infrastructure team unemployed?
All-inclusive infrastructure, pay-as-you-go pricing, a cloud-based AI agent working for you 24/7.

Trump Admin's $950 Million Bet on Oil Price Plunge Before Ceasefire Turned Crude Market into Insider Trading Heaven
19:45 GMT is a tricky timepoint

Why Did Trump Take the US into War with Iran?
Here is the inside story of how he made this key decision

From Threat to Ceasefire: How Did the U.S. Lose Its Dominance?
A war that cannot be won must be negotiated.

How long can the Ethereum ecosystem survive after the launch of Mythos?
AI dimensionality reduction strikes Ethereum, Mythos instantly breaches cross-contract vulnerabilities rendering traditional audits ineffective, and $68 billion in locked funds faces a life-and-death test of "defensive vacuum."

Morning News | Yi Lihua establishes AI fund OpenX Labs; Pharos Network completes $44 million Series A financing; Iran demands that Hormuz tankers pay Bitcoin as tolls
Overview of Important Market Events on April 8th

Ray Dalio's new article: The world is entering a war cycle
We are in a world war that will not end in the short term.

IOSG: When Fintech Meets Crypto Native: The Next Decade of Digital Finance
Header: FinTech is increasingly integrating stablecoins and blockchain infrastructure into core products, reshaping the global payment landscape.

They knew in advance that Trump would tweet about a ceasefire, entered with $20k, and exited with $400k.
They turned the war into a compounding investment

The biggest bottleneck in DeFi development
Today, the biggest threat facing DeFi is not just market conditions or liquidity; in terms of security, it also requires more than just preventing code vulnerabilities, because spies may be lurking nearby.

CZ Memoir Released: Reveals a Large Amount of Industry Insider Information, Prompting Intense Rebuttal from Xu Mingxing
As one of the most influential figures in the cryptocurrency industry today, Zhao Changpeng has personally experienced the difficult development journey of Binance and the cryptocurrency industry in its early years, which brings many little-known insider stories and details to this book, adding plen...

a16z: After securities are on the blockchain, why will intermediary institutions be replaced by code?
Writing transactions and settlements into code, the securities market begins to break free from intermediaries.

XRP Tokyo Is Here: What We Learn and What’s Next for XRP Price
Key Takeaways: Ripple’s 2025 XRP Tokyo event highlights a projected $33 trillion on-chain stablecoin volume by 2026. Significant…

Solana’s Future: Navigating the $285M Hack, Rug Pulls, and Milei Libra Scandal
Key Takeaways: Multiple Crises: Solana faces a $285 million hack, allegations of rug pulls, and the Milei Libra…
Once you're over 25, you're already too old to be playing with meme coins.
Pump.fun, the world's largest 24-hour online esports platform
Four New Frontlines Post Ceasefire | Rewire News Daily Brief
Rate Cut Window Pushed Beyond Year End
Holmez accepts Bitcoin for toll payment, how much can Iran earn?
When you stretch the numbers and do the math, the answer turns out to be unexpectedly small
When No One on the Team Wants to Sell: The Valuation Game at Anthropic Enters the “Seller Disappearance” Stage
Anthropic's stock, priced at $350 billion, some want to buy but can't buy enough, some can sell but unwilling to sell.
Anthropic's new product, powerful enough to make the AI Agent Infrastructure team unemployed?
All-inclusive infrastructure, pay-as-you-go pricing, a cloud-based AI agent working for you 24/7.
Trump Admin's $950 Million Bet on Oil Price Plunge Before Ceasefire Turned Crude Market into Insider Trading Heaven
19:45 GMT is a tricky timepoint
