Friday, April 17, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

FBI shuts down crypto fraud site linked to Lazarus Group

by SB Crypto Guru News
April 25, 2025
in Scam Alert
Reading Time: 3 mins read
0 0
A A
0


FBI shuts down crypto fraud site linked to Lazarus Group
  • Hackers posed as tech recruiters in fake job interviews.
  • Malware used to steal crypto wallets and credentials.
  • Front firms traced to addresses in South Carolina and Buffalo.

North Korea’s covert cyberwarfare strategy has taken a new turn, with US federal investigators uncovering an elaborate crypto-related malware campaign run by front companies posing as legitimate tech recruiters.

According to a report published by Reuters on Friday, hackers aligned with the North Korean government created fake businesses to deploy malicious software targeting crypto developers.

The objective: steal digital assets and sensitive credentials while evading sanctions and scrutiny.

The FBI, in coordination with cybersecurity firm Silent Push, dismantled a key piece of this operation by seizing the web domain of one of the implicated entities, Blocknovas LLC.

The move marks a widening crackdown on state-sponsored cyber threats exploiting the crypto space.

Three front companies identified in North Korea-linked scam

At the centre of the operation were three companies—Blocknovas LLC, Softglide LLC, and Angeloper Agency—set up using falsified addresses in the US.

Blocknovas and Softglide were officially registered in New Mexico and New York, respectively, while Angeloper appeared to operate without any proper registration.

Public records reviewed by Reuters showed Blocknovas was registered to an empty plot in South Carolina, and Softglide’s paperwork was linked to a modest tax consultancy in Buffalo.

The FBI confirmed on Thursday that it had seized Blocknovas’ domain.

Silent Push identified it as the most active of the three entities, having already compromised multiple victims in the crypto space.

These companies were reportedly operated by cyber operatives tied to the Lazarus Group, a unit under North Korea’s Reconnaissance General Bureau.

This agency oversees many of Pyongyang’s foreign intelligence and hacking operations.

Malware deployed through fake job interviews

The technique employed was both deceptive and effective. According to the FBI and Silent Push, North Korean hackers posed as recruiters offering fake job interviews to unsuspecting crypto developers.

These developers, lured by lucrative offers, were eventually tricked into downloading malware.

Once installed, the malware provided attackers with access to crypto wallets and development environments, enabling unauthorised transactions and theft of confidential credentials.

The entire campaign appears designed not only to steal funds but also to enable deeper breaches into platforms that build or manage digital assets.

Such tactics are seen as an evolution of previous cyber operations linked to North Korea, where malware distribution and phishing attempts were mainly directed at exchanges and DeFi protocols.

Crypto crimes seen as key revenue stream for weapons programme

This malware campaign underscores North Korea’s growing reliance on cybercrime to finance its international ambitions.

UN reports and independent investigations have shown that the regime is increasingly turning to cryptocurrency theft as a means to fund its nuclear and ballistic missile programmes.

In 2022, the regime was linked to the infamous Axie Infinity hack, which resulted in over $600 million in losses.

More recently, it has been revealed that thousands of IT professionals have been sent abroad to work covertly for firms in return for crypto payments, which are then funnelled back into North Korea’s coffers.

All of these efforts directly violate sanctions imposed by the US Treasury’s Office of Foreign Assets Control (OFAC) and several United Nations resolutions aimed at curbing North Korea’s access to international funding channels.

As investigations continue, cybersecurity experts warn that more such front companies may exist and that developers and crypto firms must heighten their due diligence processes when approached with unsolicited job offers.


Share this article

Categories

Tags



Source link

Tags: Bitcoin NewsCryptoCrypto NewsCrypto UpdatesFBIfraudGroupLatest News on CryptoLazaruslinkedSB Crypto Guru Newsshutssite
Previous Post

Bitcoin Dries Up on Exchanges as Public Firms Keep Buying

Next Post

Is This Crypto Bot Legit, Safe & Available in the US?

Related Posts

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

by SB Crypto Guru News
April 14, 2026
0

Make CryptoSlate preferred on Kraken says it is being extorted by a criminal group threatening to release internal material after...

DOJ seizures of 0M expose how crypto investment scams scaled into shift work with quotas and scripts

DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

by SB Crypto Guru News
March 1, 2026
0

For years, the wrong-number text arrived like clockwork. A friendly mistake, then apologies, small talk, and gradual friendship. Eventually, the...

MakinaFi hit by .1M Ethereum hack as MEV tactics suspected

MakinaFi hit by $4.1M Ethereum hack as MEV tactics suspected

by SB Crypto Guru News
January 20, 2026
0

Funds were split between two wallets holding $3.3 million and $880,000. The exploit involved MEV-linked addresses and preemptive transaction timing....

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

by SB Crypto Guru News
January 16, 2026
0

Group-IB published its report on Jan. 15 and said the method could make disruption harder for defenders. The malware reads...

Tether freezes 2M in USDT, highlighting centralized control in stablecoins

Tether freezes $182M in USDT, highlighting centralized control in stablecoins

by SB Crypto Guru News
January 12, 2026
0

The action was detected by Whale Alert and ranks among the largest single-day USDT freezes. Tether has frozen over $3...

Load More
Next Post
Is This Crypto Bot Legit, Safe & Available in the US?

Is This Crypto Bot Legit, Safe & Available in the US?

Top 10 Crypto Accounts to Follow on X

Top 10 Crypto Accounts to Follow on X

Facebook Twitter LinkedIn Tumblr RSS

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.