financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
Aug 16, 2025 8:58 PM

Investigations by popular blockchain sleuth ZachXBT have uncovered extensive North Korean infiltration in the global cryptocurrency development job market.

An unnamed source recently compromised a device belonging to a DPRK IT worker and provided unprecedented insight into how a small team of five IT workers operated over 30 fake identities.

DPRK Operatives Flood Crypto Job Market

According to ZachXBTs tweets, the DPRK team reportedly used government-issued IDs to register accounts on Upwork and LinkedIn, to obtain developer roles on multiple projects. Investigators found an export of the workers Google Drive, Chrome profiles, and screenshots, which revealed that Google products were central to organizing schedules, tasks, and budgets, with communications primarily conducted in English.

Among the documents is a 2025 spreadsheet containing weekly reports from team members, which shed light on their internal operations and mindset. Typical entries included statements such as I cant understand the job requirement, and dont know what I need to do, with self-directed notes like Solution / fix: Put enough efforts in heart.

Another spreadsheet tracks expenses, showing purchases of Social Security numbers, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, computer rentals, and VPN or proxy services. Meeting schedules and scripts for fake identities, including one under the name Henry Zhang, were also recovered.

The teams operational methods reportedly involved purchasing or renting computers, using AnyDesk to perform work remotely, and converting earned fiat into cryptocurrency via Payoneer. One wallet address, 0x78e1, associated with the group is linked on-chain to a $680,000 exploit at Favrr in June 2025, where the projects CTO and other developers were later identified as DPRK IT workers using fraudulent documents. Additional DPRK-linked workers were connected to projects via the 0x78e1 address.

Indicators of their North Korean origin include frequent use of Google Translate for Korean-language searches conducted from Russian IP addresses. ZachXBT said that these IT workers are not particularly sophisticated, but their persistence is bolstered by the sheer number of roles they target across the world.

Challenges in countering these operations include poor collaboration between private companies and services, as well as resistance from teams when fraudulent activity is reported.

North Koreas Persistent Threat

North Korean hackers, notably the Lazarus Group, continue to pose a significant threat to the industry. In February 2025, the group orchestrated the largest crypto exchange hack in history, as it stole approximately $1.5 billion in Ethereum from Dubai-based Bybit.

The attack exploited vulnerabilities in a third-party wallet provider, Safe{Wallet}, which allowed the hackers to bypass multi-signature security measures and siphon funds into multiple wallets. The FBI attributed the breach to North Korean operatives, labeling it TraderTraitor.

Subsequently, in July 2025, CoinDCX, an Indian cryptocurrency exchange, fell victim to a $44 million heist, which was also linked to the Lazarus Group. The attackers infiltrated CoinDCXs liquidity infrastructure, exploiting exposed internal credentials to execute the theft.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Bitcoin Price Analysis: Is $80K Next for BTC After Losing 2 Key Support Lines?
Bitcoin Price Analysis: Is $80K Next for BTC After Losing 2 Key Support Lines?
Feb 26, 2025
Bitcoin’s price has been going through a significant drop over the last couple of days, losing a key support level. However, there is still a good chance for the market to rebound soon. Technical Analysis By Edris Derakhshi (TradingRage) The Daily Chart On the daily chart, the largest cryptocurrency has been dropping rapidly this week, breaking below the key $92K...
Santiment: Bitcoin, Ethereum, Ripple, and Solana See Widespread FUD
Santiment: Bitcoin, Ethereum, Ripple, and Solana See Widespread FUD
Feb 26, 2025
The cryptocurrency market is facing intense fear, uncertainty, and doubt (FUD), with sentiment around several top assets at extreme bearish levels. Bitcoin (BTC), Ethereum (ETH), Ripple (XRP), and Solana (SOL) have all suffered significant declines, pushing traders into panic mode, but history suggests a potential bottom may be near. Market Sentiment Hits Rock Bottom According to on-chain analytics from the...
ETH Risks Falling to $2K if This Support Fails: Ethereum Price Analysis
ETH Risks Falling to $2K if This Support Fails: Ethereum Price Analysis
Feb 26, 2025
Ethereum’s price has been dropping consistently over the past few months since it was rejected from the $4,000 level. Meanwhile, there is still the possibility for a deeper decline in the coming weeks. Technical Analysis By Edris Derakhshi (TradingRage) The Daily Chart On the daily chart, the asset has been trending lower since it failed to break above the $4,000...
Important Binance Announcement Affecting Ukrainian Users: Details
Important Binance Announcement Affecting Ukrainian Users: Details
Feb 26, 2025
TL;DR Binance will remove the BNB/UAH and ETH/UAH trading pairs, limiting direct access for Ukrainian traders to these cryptocurrencies. Meanwhile, the prices of Binance Coin (BNB) and Ethereum (ETH) remain stable today amid the markets rebound. The Upcoming Amendment The worlds largest crypto exchange regularly monitors its services to protect users and maintain a high-quality trading market. It conducts periodic...
Copyright 2023-2026 - www.financetom.com All Rights Reserved