financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
Aug 16, 2025 8:58 PM

Investigations by popular blockchain sleuth ZachXBT have uncovered extensive North Korean infiltration in the global cryptocurrency development job market.

An unnamed source recently compromised a device belonging to a DPRK IT worker and provided unprecedented insight into how a small team of five IT workers operated over 30 fake identities.

DPRK Operatives Flood Crypto Job Market

According to ZachXBTs tweets, the DPRK team reportedly used government-issued IDs to register accounts on Upwork and LinkedIn, to obtain developer roles on multiple projects. Investigators found an export of the workers Google Drive, Chrome profiles, and screenshots, which revealed that Google products were central to organizing schedules, tasks, and budgets, with communications primarily conducted in English.

Among the documents is a 2025 spreadsheet containing weekly reports from team members, which shed light on their internal operations and mindset. Typical entries included statements such as I cant understand the job requirement, and dont know what I need to do, with self-directed notes like Solution / fix: Put enough efforts in heart.

Another spreadsheet tracks expenses, showing purchases of Social Security numbers, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, computer rentals, and VPN or proxy services. Meeting schedules and scripts for fake identities, including one under the name Henry Zhang, were also recovered.

The teams operational methods reportedly involved purchasing or renting computers, using AnyDesk to perform work remotely, and converting earned fiat into cryptocurrency via Payoneer. One wallet address, 0x78e1, associated with the group is linked on-chain to a $680,000 exploit at Favrr in June 2025, where the projects CTO and other developers were later identified as DPRK IT workers using fraudulent documents. Additional DPRK-linked workers were connected to projects via the 0x78e1 address.

Indicators of their North Korean origin include frequent use of Google Translate for Korean-language searches conducted from Russian IP addresses. ZachXBT said that these IT workers are not particularly sophisticated, but their persistence is bolstered by the sheer number of roles they target across the world.

Challenges in countering these operations include poor collaboration between private companies and services, as well as resistance from teams when fraudulent activity is reported.

North Koreas Persistent Threat

North Korean hackers, notably the Lazarus Group, continue to pose a significant threat to the industry. In February 2025, the group orchestrated the largest crypto exchange hack in history, as it stole approximately $1.5 billion in Ethereum from Dubai-based Bybit.

The attack exploited vulnerabilities in a third-party wallet provider, Safe{Wallet}, which allowed the hackers to bypass multi-signature security measures and siphon funds into multiple wallets. The FBI attributed the breach to North Korean operatives, labeling it TraderTraitor.

Subsequently, in July 2025, CoinDCX, an Indian cryptocurrency exchange, fell victim to a $44 million heist, which was also linked to the Lazarus Group. The attackers infiltrated CoinDCXs liquidity infrastructure, exploiting exposed internal credentials to execute the theft.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Bitcoin Price Analysis: Will a Key Support Break Trigger More Losses for BTC?
Bitcoin Price Analysis: Will a Key Support Break Trigger More Losses for BTC?
Sep 2, 2025
Bitcoin has entered a corrective phase after its recent all-time high, with the price consolidating at key supports and on-chain data showing increased profit-taking. Market sentiment is cautious, and the next move will decide whether the pullback extends or a fresh bullish leg begins. By Shayan The Daily Chart BTC has broken down from its rising channel after failing to...
Ripple Price Analysis: Is XRP Preparing for a Big Move as Consolidation Nears Finale?
Ripple Price Analysis: Is XRP Preparing for a Big Move as Consolidation Nears Finale?
Sep 2, 2025
Ripple’s price has been stuck in consolidation for the past few weeks without establishing a clear trend against both USDT and BTC. At the moment, it is sitting at a crucial level that could dictate the next major move, potentially sparking a strong breakout in the near term. Technical Analysis By Shayan The USDT Pair XRP has been consolidating inside...
Ripple Breakout Watch: XRP’s Future Rests on This Crucial Support
Ripple Breakout Watch: XRP’s Future Rests on This Crucial Support
Sep 2, 2025
TL;DR XRP tests crucial $2.65 support; failure risks $2.50–$2.33, while holding could fuel rebound. Analysts see breakout levels at $2.85, $2.95, and $3.13, with $3.40 signaling new ATH. The asset also formed a spinning bottom pattern, which could lead to a bullish reversal. XRP Retests Crucial Support at $2.65 XRP is testing the $2.65 support level, seen as critical to...
Strategy Spends $450 Million to Acquire Additional 4,048 BTC
Strategy Spends $450 Million to Acquire Additional 4,048 BTC
Sep 2, 2025
Michael Saylors business intelligence giant has resumed its bitcoin accumulation spree by spending just under $450 million to acquire 4,048 BTC at an average price of $110,981. The companys gigantic stash has risen to 636,505 BTC. The firm has spent almost $47 billion to build its holdings, which are now worth roughly $70 billion, given bitcoins price of just under...
Copyright 2023-2026 - www.financetom.com All Rights Reserved