{"id":19720,"date":"2025-05-02T02:38:29","date_gmt":"2025-05-02T02:38:29","guid":{"rendered":"https:\/\/gold.creditcard\/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview\/"},"modified":"2025-05-02T02:38:29","modified_gmt":"2025-05-02T02:38:29","slug":"kraken-details-how-it-spotted-north-korean-hacker-in-job-interview","status":"publish","type":"post","link":"https:\/\/gold.creditcard\/es\/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview\/","title":{"rendered":"Kraken details how it spotted North Korean hacker in job interview"},"content":{"rendered":"<p>US crypto exchange Kraken has detailed a North Korean hacker\u2019s attempt to infiltrate the organization by applying for a job interview.<\/p>\n<p>\u201cWhat started as a routine hiring process for an engineering role quickly turned into an intelligence-gathering operation,\u201d the company <a href=\"https:\/\/blog.kraken.com\/news\/how-we-identified-a-north-korean-hacker\" target=\"null\" title=\"null\">wrote<\/a> in a May 1 blog post.<\/p>\n<p>Kraken said the applicant\u2019s red flags appeared early on in the process when they joined an interview under a name different from what they applied with and \u201coccasionally switched between voices,\u201d apparently being guided through the interview.<\/p>\n<p>Rather than immediately rejecting the applicant, Kraken decided to advance them through its hiring process to gather information about the tactics used.<\/p>\n<p>International sanctions have effectively cut North Korea off from the rest of the world, and the country\u2019s ruling Kim family dictatorship has long targeted crypto companies and users to top up the country\u2019s coffers. It\u2019s stolen billions worth of crypto so far this year.<\/p>\n<p><a href=\"https:\/\/cointelegraph.com\/news\/crypto-exchange-kraken-exploring-1-billion-raise-report\" target=\"null\" title=\"null\">Kraken<\/a> reported that industry partners had tipped them off that North Korean actors were actively applying for jobs at crypto companies.\u00a0<\/p>\n<p>\u201cWe received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken,\u201d it said.\u00a0<\/p>\n<p>With this information, the firm\u2019s security team uncovered a network of fake identities used by the hacker to apply to multiple companies.\u00a0<\/p>\n<p>Kraken also noted technical inconsistencies, which included the use of remote Mac desktops through VPNs and altered identification documents.<\/p>\n<p>Kraken CSO <a href=\"https:\/\/twitter.com\/c7five?ref_src=twsrc%5Etfw\">@c7five<\/a> recently spoke to <a href=\"https:\/\/twitter.com\/CBSNews?ref_src=twsrc%5Etfw\">@CBSNews<\/a> about how a North Korean operative unsuccessfully attempted to get a job at Kraken. <\/p>\n<p>Don\u2019t trust. Verify \ud83d\udc47 <a href=\"https:\/\/t.co\/1vVo3perH2\">pic.twitter.com\/1vVo3perH2<\/a><\/p>\n<p>\u2014 Kraken Exchange (@krakenfx) <a href=\"https:\/\/twitter.com\/krakenfx\/status\/1917945763088236808?ref_src=twsrc%5Etfw\">May 1, 2025<\/a><\/p>\n<p>The applicant\u2019s resume was linked to a GitHub profile containing an email address exposed in a past data breach, and the exchange said the candidate\u2019s primary form of ID \u201cappeared to be altered, likely using details stolen in an identity theft case two years prior.\u201d<\/p>\n<p>During final interviews, Kraken chief security officer Nick Percoco conducted trap <a href=\"https:\/\/cointelegraph.com\/news\/sam-altman-eye-scanning-crypto-project-worldcoin-launches-us\" target=\"null\" title=\"null\">identity verification<\/a> tests that the candidate failed, confirming the deception.\u00a0<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/lazarus-group-2024-pause-repositioning-1-4-b-bybit-hack\" target=\"null\" title=\"null\"><em><strong>Lazarus Group\u2019s 2024 pause was repositioning for $1.4B Bybit hack<\/strong><\/em><\/a><\/p>\n<p>\u201cDon\u2019t trust, verify. This core crypto principle is more relevant than ever in the digital age,\u201d Peroco said. \u201cState-sponsored attacks aren\u2019t just a crypto or US corporate issue \u2014 they\u2019re a global threat.\u201d<\/p>\n<h2>North Korea pulls off biggest-ever crypto hack<\/h2>\n<p>North Korea-affiliated hacking collective <a href=\"https:\/\/cointelegraph.com\/learn\/articles\/lazarus-group-hackers-behind-billion-dollar-heists\" target=\"null\" title=\"null\">Lazarus Group<\/a> was responsible for February\u2019s $1.4 billion <a href=\"https:\/\/cointelegraph.com\/news\/bybit-exchange-hacked\" target=\"null\" title=\"null\">Bybit exchange hack<\/a>, the largest ever for the crypto industry.<\/p>\n<p>North Korean-linked hackers also stole more than $650 million through multiple crypto heists during 2024, while deploying IT workers to infiltrate blockchain and crypto companies as insider threats, <a href=\"https:\/\/www.mofa.go.jp\/files\/100779661.pdf\" target=\"null\" title=\"null\">according<\/a> to a statement released by the US, Japan and South Korea in January.\u00a0<\/p>\n<p>In April, a subgroup of Lazarus was found to have set up <a href=\"https:\/\/cointelegraph.com\/news\/lazarus-set-up-us-shell-companies-scam-crypto-devs\" target=\"null\" title=\"null\">three shell companies<\/a>, with two in the US, to deliver malware to unsuspecting users and scam crypto developers.\u00a0<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/jav-porn-star-crypto-mikami-ethereum-rwa-l2-alibaba-asia-express\/\" target=\"null\" title=\"null\"><em><strong>Japanese porn star\u2019s coin red flags, Alibaba-linked L2 runs at 100K TPS: Asia Express<\/strong><\/em><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>US crypto exchange Kraken has detailed a North Korean hacker\u2019s attempt to infiltrate the organization by applying for a job interview. \u201cWhat started as a routine hiring process for an engineering role quickly turned into an intelligence-gathering operation,\u201d the company wrote in a May 1 blog post. Kraken said the applicant\u2019s red flags appeared early [&hellip;]<\/p>","protected":false},"author":0,"featured_media":19721,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[],"class_list":["post-19720","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-finance"],"_links":{"self":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/19720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/comments?post=19720"}],"version-history":[{"count":0,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/19720\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media\/19721"}],"wp:attachment":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media?parent=19720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/categories?post=19720"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/tags?post=19720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}