2025-04-02 17:45:40
5

朝鲜 IT 工作者加紧渗透欧洲各地科技和加密货币公司

朝鲜 IT 工作者加紧渗透欧洲各地科技和加密货币公司

朝鲜 IT 工作者正在加大对科技和加密货币公司的渗透力度,重点是欧洲。

自 2024 年 9 月发布上一份报告以来,谷歌威胁情报小组发现朝鲜 IT 工作者渗透欧洲多个国家的科技和加密货币公司的情况有所增加。这些人使用虚假身份并创建多个虚假角色,以确保在科技和区块链公司获得高薪工作,通常使用其他虚构角色作为参考。在一个案例中,发现一名个人在欧洲和美国以至少 12 个不同的身份开展活动,目标是国防和政府部门的组织。


North Korean IT workers ramp up infiltration of tech and crypto firms across Europe - 1
Source: List of countries impacted by DPRK IT workers

根据最新报道,一些朝鲜 IT 工作者被发现积极参与英国的区块链项目,例如开发 Solana 和 Anchor/Rust 智能合约,以及使用 MERN 堆栈和 Solana 构建基于区块链的工作市场。

除了 IT 工作者本身之外,调查还发现了一个协助这些工作者浏览欧洲求职网站并向他们提供虚假身份证明文件的协助者网络。

朝鲜积极扩大 IT 工作者渗透,很大程度上是出于该政权需要规避限制其进入全球金融系统的国际制裁。随着经济压力不断增加,该国已将网络运营作为主要收入来源,利用 IT 工作者获得高薪工作并将收入汇回国家。2022 年,美国财政部估计,这些工人每年为朝鲜创造数亿美元收入。朝鲜政府扣留了这些工人高达 90% 的工资,从而将大量资金投入其军事项目。

Beyond directly funneling their salaries to the regime, North Korean IT workers sometimes act as entry points for state-sponsored hacking groups like Lazarus Group, which was recently in the spotlight for orchestrating the $1,5 billion hack of Bybit exchange. Notably, Lazarus stole over $600 million from the Ronin Network (Axie Infinity) in 2022, with IT workers playing a key role in providing access to internal systems. In August 2024, on-chain sleuth ZachXBT uncovered over 25 crypto projects infiltrated by DPRK devs.

While Lazarus’s hack of Bybit—after which North Korea became the fifth-largest government holder of Bitcoin (BTC)—was linked to the exploitation of vulnerabilities in its multi-sig wallet rather than direct infiltration, it has raised awareness of the DPRK’s threat in the U.S. According to GTIG report, this heightened awareness is one of the key factors behind the expansion of North Korean infiltration efforts into Europe, in addition to increased public reporting, U.S. Department of Justice indictments, and challenges related to right-to-work verification.

声明:文章不代表币特网观点及立场,不构成本平台的投资建议,转载联系作者并注明出处:然后加上这个内页的网址: https://m.bitcoin688.com/news/58065.html
回顶部