financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Google Docs, Upwork, and LinkedIn: Inside North Korean IT Workers’ Secret Crypto Operations
Aug 16, 2025 8:58 PM

Investigations by popular blockchain sleuth ZachXBT have uncovered extensive North Korean infiltration in the global cryptocurrency development job market.

An unnamed source recently compromised a device belonging to a DPRK IT worker and provided unprecedented insight into how a small team of five IT workers operated over 30 fake identities.

DPRK Operatives Flood Crypto Job Market

According to ZachXBTs tweets, the DPRK team reportedly used government-issued IDs to register accounts on Upwork and LinkedIn, to obtain developer roles on multiple projects. Investigators found an export of the workers Google Drive, Chrome profiles, and screenshots, which revealed that Google products were central to organizing schedules, tasks, and budgets, with communications primarily conducted in English.

Among the documents is a 2025 spreadsheet containing weekly reports from team members, which shed light on their internal operations and mindset. Typical entries included statements such as I cant understand the job requirement, and dont know what I need to do, with self-directed notes like Solution / fix: Put enough efforts in heart.

Another spreadsheet tracks expenses, showing purchases of Social Security numbers, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, computer rentals, and VPN or proxy services. Meeting schedules and scripts for fake identities, including one under the name Henry Zhang, were also recovered.

The teams operational methods reportedly involved purchasing or renting computers, using AnyDesk to perform work remotely, and converting earned fiat into cryptocurrency via Payoneer. One wallet address, 0x78e1, associated with the group is linked on-chain to a $680,000 exploit at Favrr in June 2025, where the projects CTO and other developers were later identified as DPRK IT workers using fraudulent documents. Additional DPRK-linked workers were connected to projects via the 0x78e1 address.

Indicators of their North Korean origin include frequent use of Google Translate for Korean-language searches conducted from Russian IP addresses. ZachXBT said that these IT workers are not particularly sophisticated, but their persistence is bolstered by the sheer number of roles they target across the world.

Challenges in countering these operations include poor collaboration between private companies and services, as well as resistance from teams when fraudulent activity is reported.

North Koreas Persistent Threat

North Korean hackers, notably the Lazarus Group, continue to pose a significant threat to the industry. In February 2025, the group orchestrated the largest crypto exchange hack in history, as it stole approximately $1.5 billion in Ethereum from Dubai-based Bybit.

The attack exploited vulnerabilities in a third-party wallet provider, Safe{Wallet}, which allowed the hackers to bypass multi-signature security measures and siphon funds into multiple wallets. The FBI attributed the breach to North Korean operatives, labeling it TraderTraitor.

Subsequently, in July 2025, CoinDCX, an Indian cryptocurrency exchange, fell victim to a $44 million heist, which was also linked to the Lazarus Group. The attackers infiltrated CoinDCXs liquidity infrastructure, exploiting exposed internal credentials to execute the theft.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Binance Co
Binance Co
Nov 4, 2024
Binance co-founder Yi He has spoken to recent speculation about listing fees on the platform, assuring the community that it operates with transparent policies. The address came in response to allegations by Moonrock Capital CEO Simon Dedic of costly listing fees on Binance. Binance Accused of Charging Exorbitant Fees for Crypto Listing On October 31, Dedic took to X with...
These 2 Exchanges Lead in Bitcoin Reserve Growth Since FTX’s 2022 Collapse
These 2 Exchanges Lead in Bitcoin Reserve Growth Since FTX’s 2022 Collapse
Nov 4, 2024
The FTX collapse of November 2022 continues to serve as a stark reminder of the necessity for rigorous asset monitoring. This event catalyzed a shift toward transparency, with crypto exchanges now disclosing more about their reserves and user fund management. As November 6th marks two years since the collapse, only Bitfinex and Binance witnessed their Bitcoin reserves grow out of...
Chinese E
Chinese E
Nov 4, 2024
In line with a broader trend among major tech firms, Chinese e-commerce behemoth Alibaba is downsizing its metaverse operations. The restructuring, which aims to improve efficiency, led to layoffs in Yuanjing, Alibabas metaverse unit, as the company recalibrates its focus in this sector. Downsizing Metaverse Unit According to the report by South China Morning Post, which is also owned by...
Top Ripple (XRP) Price Predictions as of Late
Top Ripple (XRP) Price Predictions as of Late
Nov 4, 2024
TL;DR Analysts foresee a potential XRP rally, envisioning a surge to $0.90 if the asset clears crucial resistance points, despite recent underperformance. The US presidential election results could fuel enhanced volatility for the entire crypto market and Ripples native token particularly. Bearish Outlook or a Strong Bullish Trend? Despite its slight resurgence in the past 24 hours, Ripples XRP remains...
Copyright 2023-2025 - www.financetom.com All Rights Reserved