Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (3,558)
  • Analysis (3,667)
  • Bitcoin (4,290)
  • Blockchain (2,157)
  • DeFi (2,623)
  • Ethereum (2,757)
  • Event (119)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,714)
  • Press Releases (12)
  • Reddit (2,847)
  • Regulation (2,474)
  • Security (3,979)
  • Thought Leadership (3)
  • Videos (44)
Hand picked
  • Sahara AI Surges: Can Its Price Recovery Survive a 1.03 Billion Token Unlock?
  • Major Ripple (XRP) Adoption News for Users in Japan: Details
  • THORChain Resumes Trading After $10.7 Million Exploit and Upgrades
  • How Steak and Shake Bitcoin Payments Could Save $6 Million a Year in Fees
  • Venice Token Drops 11% – Why THIS Level Could Decide VVV’s Next Move
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Analysis»The Lazare group in North Korea sets up fictitious American companies to cultivate development portfolios
Analysis

The Lazare group in North Korea sets up fictitious American companies to cultivate development portfolios

April 25, 2025No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
1ad8b72d 774f 4876 b0f4 c0f6dca1468b 800x420.jpg
Share
Facebook Twitter LinkedIn Pinterest Email


Main to remember

  • The Lazare group has created false American companies to target developers of the cryptographic industry with Malware.
  • The operation represents an evolution of the efforts of North Korea to target the cryptography sector for funding.

Share this article







The Lazarus group of North Korea, through its sub-unit, has shot false companies registered in the United States as part of a campaign for phish Crypto developers and steal their portfolios, according to a new Reuters report.

Companies, Blocknovas LLC and SoftGlide LLC, were recorded in New Mexico and New York using false personalities and addresses. Another entity, Angeloper Agency, would be connected to the operation, but it is not recorded in the United States.

The diagram

Tactics have consisted in creating false companies, establishing a convincing online presence and publishing job lists targeting developers.

The pirates used false identities, invented addresses and real platforms like Linkedin and Upwork to appear legitimate and attract developers. Once the candidates have opted for the candidates, they were taken by false interviews and asked to download test assignments or software.

These files contained malicious software which, once executed, gave attackers access to the victim’s system, allowing them to extract passwords, cryptographic wallet keys and other sensitive data.

The Russian -speaking group used almost identical tactics in the previous campaign

In February, BleepingCompute reported that Crazy Evil, a Russian cybercrime group, had already deployed comparable tactics in a targeted scam against crypto and web job seekers.

A subgroup of Crazy Evil has created a false business called chaunseeker.io, displaying fraudulent announcements on platforms like LinkedIn. The candidates were invited to download a malicious application, Grasscall, which installed malware designed to steal identification information, cryptographic wallets and sensitive files.

The operation was well coordinated, using cloned websites, false profiles and a telegram to distribute malicious software.

The FBI confirms the North Korean link

Kasey Best, intelligence director of threats to Silent Push, said that it was one of the first known cases of North Korean pirates that set up legally recorded companies in the United States to circumvent and obtain credibility.

Silent Push retraced the pirates to the Lazare group and confirmed several victims of the campaign, identifying Blocknovas as the most active of the three leading companies they have discovered.

The FBI seized the Blocknovas Domaine as part of application actions against North Korean cyber-actors who used false job offers to distribute malware.

FBI officials said they continue to “focus on the taxation of risks and consequences, not only on the actors of the RPDC themselves, but for anyone facilitating their ability to carry out these diets”.

According to an FBI official, North Korean cyber operations are among the country’s most sophisticated persistent threats.

North Korea exploits the Russian infrastructure on the scale of attacks

To overcome limited national internet access, the North Korea hacking group uses international infrastructure, in particular Russian intellectual property ranges organized in Khasan and Khabarovsk, cities with direct links with North Korea, according to an in -depth analysis of Trend Micro.

The use of VPN, RDP sessions and proxy services like Astrill VPN and CCProxy, Lazarus agents are able to manage attacks, to communicate via Github and Slack, and access to platforms such as Upwork and Telegram.

Silent Push researchers identified seven educational videos recorded by accounts related to Blocknovas as part of the operation. The videos describe how to configure command and control servers, steal browser passwords, download stolen data on Dropbox and break cryptographic wallets with tools such as Hashtopolis.

From the flight to spying sponsored by the State

Hundreds of developers have been targeted, many exposing their sensitive references without knowing it. Some violations seem to have increased beyond the flight, suggesting that Lazarus may have given access to other teams aligned by the State for spying purposes.

US, South Korean and UN officials have confirmed to Reuters that North Korea pirates had deployed thousands of IT workers abroad to generate millions of funds for the Pyongyang nuclear missile program.

Share this article









Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDo Dogecoin millionaires accumulate this hidden altcoin in the prevented stage, do they know something that you do not do it?
Next Article Safety and mantle launch funds – Crypto response to S&P 500

Related Posts

Analysis

Major Ripple (XRP) Adoption News for Users in Japan: Details

June 25, 2026
Analysis

Ethereum News: Ethereum Foundation Cuts 20% of Its Staff and Transforms into Five Protocol Clusters

June 25, 2026
Analysis

SBI and Startale put yen stablecoins back in the institutional spotlight

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Dutch Blockchain Week 2026 strengthens position as Europe’s leading B2B blockchain event week

April 14, 2026

Amsterdam, April 2026 – Dutch Blockchain Week 2026 is rapidly evolving into one of Europe’s…

Event

Global Games Show Riyadh: The Ultimate Creator & Influencer Hub

March 31, 2026

The fast-evolving gaming ecosystem of Riyadh is powered by solid national investment, a flourishing esports…

1 2 3 … 82 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Sahara AI Surges: Can Its Price Recovery Survive a 1.03 Billion Token Unlock?

June 25, 2026

Venice Token Drops 11% – Why THIS Level Could Decide VVV’s Next Move

June 25, 2026

Algorand forms 2 bullish patterns, but THIS group needs to intervene

June 24, 2026
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2026 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 61,823.00
ethereum
Ethereum (ETH) $ 1,654.87
tether
Tether (USDT) $ 0.998462
bnb
BNB (BNB) $ 570.27
usd-coin
USDC (USDC) $ 0.999741
xrp
XRP (XRP) $ 1.09
solana
Solana (SOL) $ 69.31
tron
TRON (TRX) $ 0.328976
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05