logo
Why are North Korean hackers such good crypto-thieves?

Why are North Korean hackers such good crypto-thieves?

Mint3 days ago

FEBRUARY 21st was a typical day, recalls Ben Zhou, the boss of ByBit, a Dubai-based cryptocurrency exchange. Before going to bed, he approved a fund transfer between the firm's accounts, a 'typical manoeuvre" performed while servicing more than 60m users around the world. Half an hour later he got a phone call. 'Ben, there's an issue," his chief financial officer said, voice shaking. 'We might be hacked…all of the Ethereum is gone."
Independent investigators and America's Federal Bureau of Investigations (FBI) soon pointed the finger at a familiar culprit: North Korea. Hackers from the hermit kingdom have established themselves as one of the biggest threats to the crypto-industry—and as a crucial source of revenue for Kim Jong Un's regime, helping it to weather international sanctions, to pamper its elites and to fund its missile and nuclear-weapons programmes.
In 2023 North Korean hackers made away with a total of $661m, according to Chainalysis, a crypto-investigations firm; they doubled the sum in 2024, racking up $1.34bn across 47 separate heists, an amount equivalent to more than 60% of the global total of stolen crypto. The ByBit operation indicates a growing degree of skill and ambition: in a single hack, North Korea swiped the equivalent of $1.5bn from the exchange, the largest-ever heist in the history of cryptocurrency.
North Korea's plunder is the payoff from a decades-long effort. The country's first computer-science schools date back to at least the 1980s. The Gulf War helped the regime recognise the importance of networked technology for modern warfare. Talented maths students were put into special schools and given reprieves from mandatory annual countryside labour, says Thae Yong Ho, a senior North Korean diplomat who defected in 2016. Originally envisaged as a tool for espionage and sabotage, North Korea's cyber-forces began to focus on cybercrime in the mid-2010s. Mr Kim is said to call cyberwarfare 'an all-purpose sword".
Stealing crypto involves two main phases. The first is breaching a target's systems—the digital equivalent of finding an underground passageway to a bank's vaults. Phishing emails can insert malicious code. North Korean operatives pose as recruiters and entice software developers to open infected files during fake job interviews. Another approach involves using fake identities to get hired at remote IT jobs with foreign companies, which can be a first step to accessing accounts. 'They've become really good at finding vulnerabilities through social engineering," says Andrew Fierman of Chainalysis. In the ByBit case, hackers compromised the computer of a developer working for a provider of digital wallet software.
Once stolen, the cryptocurrency has to be laundered. Dirty money is spread across multiple digital wallets, combined with clean funds and transferred between different cryptocurrencies, processes known in the industry as 'mixing" and 'chain hopping". 'They're the most sophisticated crypto launderers we've ever come across," says Tom Robinson of Elliptic, a blockchain-analytics firm. Finally, the stolen funds need to be cashed out.
A growing array of underground services, many linked to Chinese organised crime, can help with this. Fees and interdictions by law enforcement reduce the overall take, but North Korea can expect to receive 'definitely 80%, maybe 90%" of the funds it steals, says Nick Carlsen, a former FBI analyst now with TRM Labs, a blockchain-intelligence firm.
North Korea has several strengths. One is talent. This could appear counterintuitive: the country is desperately poor and ordinary citizens have severely restricted access to the internet or even computers. But 'North Korea can take the best minds and tell them what to do," says Kim Seung-joo of the school of cybersecurity at Korea University in Seoul. 'They don't have to worry about them going to work at Samsung." At the International Collegiate Programming Contest in 2019, a team from a North Korean university came eighth, beating those from Cambridge, Harvard, Oxford and Stanford.
Those talents are also exploited. North Korean hackers work around the clock. They are unusually brazen when they strike. Most state actors seek to avoid diplomatic blowback and 'operate like they're in Ocean's 11: white gloves, get in without anyone noticing, steal the crown jewel, get out without being noticed," says Jenny Jun of the Georgia Institute of Technology. North Korea does not 'place a premium on secrecy—they're not afraid to be loud."
For the North Korean regime, stolen crypto has become a lifeline, especially as international sanctions and the covid-19 pandemic crimped their already limited trade. Crypto-thievery is a more efficient way to earn hard currency than traditional sources, such as overseas labourers or illegal drugs. The United Nations Panel of Experts (UNPE), a monitoring body, reported in 2023 that cyber-theft accounted for half of North Korea's foreign-currency revenue. North Korea's digital plunder last year was worth more than three times the value of its exports to China, its main trade partner. 'You take what took millions of labourers, and you can replicate that with the work of a few dozen people," says Mr Carlsen.
Those funds prop up the regime. Hard currency is used to purchase luxury goods to keep elites in line. It also probably funds weapons. The majority of North Korea's stolen crypto is thought to flow into its missile and nuclear-weapons programmes.
Cryptocurrency investigators are getting better at tracking stolen funds along the blockchain. Mainstream cryptocurrency exchanges and stable-coin issuers often co-operate with law enforcement to freeze stolen funds. In 2023 America, Japan and South Korea announced a joint effort aimed at countering North Korean cybercrime. America has sanctioned several 'mixing" service providers that North Korea has used.
Yet authorities remain a step behind. After America sanctioned North Korea's favoured mixers, the hackers switched to others offering similar services. Tackling the problem requires multilateral efforts across governments and the private sector, but such collaboration has been fraying. Russia used its UN veto to gut the UNPE last year. President Donald Trump's cuts to American development aid have hit programmes aimed at building cyber-security capacity in vulnerable countries.
By contrast, the North Korean regime is throwing ever more resources at cybercrime. South Korea's intelligence services reckon its cybercrime force grew from 6,800 people in 2022 to 8,400 last year. As the crypto-industry expands in countries with weaker regulatory oversight, North Korea has an increasingly 'rich target environment", says Abhishek Sharma of the Observer Research Foundation, an Indian think-tank. Last year, Mr Sharma notes, North Korea attacked exchanges based in India and Indonesia.
North Korea is already known to be making use of artificial intelligence in its operations. AI tools can help make phishing emails more convincing and easier to produce at scale across many languages. They can also make it easier to infiltrate companies as remote tech workers. Bad days like Mr Zhou's may become increasingly typical.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Cash-strapped Maharashtra government OKs Rs 3,000 crore for temples, memorials
Cash-strapped Maharashtra government OKs Rs 3,000 crore for temples, memorials

Time of India

time20 minutes ago

  • Time of India

Cash-strapped Maharashtra government OKs Rs 3,000 crore for temples, memorials

Maharashtra CM Fadnavis, his deputies Shinde and Pawar, and others at the Ahilyadevi Holkar memorial in Chondi earlier this month MUMBAI: The cash-strapped Maharashtra government granted approval for plans worth Rs 2,954 crore for preservation and renovation of memorials and temples in the state on Wednesday. This includes clearance for a development plan worth Rs 681.3 crore for the preservation of the memorial to the 18th-century warrior queen Ahilyadevi Holkar at her birthplace in Chaundi village in Ahilyanagar. The project was announced at a cabinet meeting held at Ahilyanagar on May 6 and comes ahead of the ruler's 300th birth anniversary. The work is to be completed over the next three years. At the same cabinet meeting, development plans worth Rs 5,503 crore were cleared for seven major pilgrimage centres in the state. This included Rs 147.8 crore for Ashtavinayak temples, Rs 1,865 crore for the Tuljabhavani temple plan, Rs 259.6 crore for the Jyotiba temple plan, Rs 275 crore for the Trimbakeshwar temple plan, Rs 1,445 crore for the Mahalaxmi Mandir plan, and Rs 829 crore for the Mahurgad development plan. On Wednesday, the government gave administrative approval to four of the seven projects. This includes theRs 147.8 crore Ashtavinayak temples development plan, in which an expenditure of Rs 100 crore will be undertaken on the temples and an expense of Rs 47.4 crore has been approved for electrification, lighting, and architectural consultancy. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Trade Bitcoin & Ethereum – No Wallet Needed! IC Markets Start Now Undo Besides the renovation of the temples, the development plan is also aimed at boosting the civic facilities available to devotees. The Ashtavinayak temples are a key tourist attraction in the state. The same day, a govt resolution was issued approving the expense of Rs 1,865 crore for the development plan of the Tuljabhavani temple at Tuljapur. Devotees come throughout the year to pray at the temple, especially during the Navratri festival. The state has issued instructions to preserve the original style of the historical structures in the temple. The state also issued a govt resolution approving the development plan for Jyotiba temple at Kolhapur worth Rs 259.6 crore. This includes plans for the conservation and renovation of the temple as well as surrounding lakes. The project is supposed to be completed by March 31, 2027.

Himanta's claims ludicrous, says Gogoi. Wait till September 10, says CM
Himanta's claims ludicrous, says Gogoi. Wait till September 10, says CM

Time of India

timean hour ago

  • Time of India

Himanta's claims ludicrous, says Gogoi. Wait till September 10, says CM

Photo/Agencies NEW DELHI/GUWAHATI: Assam CM Himanta Biswa Sarma and newly appointed Assam Congress president Gaurav Gogoi continued to skirmish on Wednesday over the former's charge that his opponent had quietly visited Pakistan. While Gogoi said the CM's "ludicrous and ridiculous" allegations were part of an unsuccessful political plot to sow seeds of doubt in the mind of Congress brass and discourage them from appointing him the state unit chief, Sarma claimed his charge had been validated with the Congress neta finally "admitting" that he had visited Pakistan. CM also said Gogoi had been economical with facts and police would soon bring out the full truth. Addressing a press conference, Gogoi said his wife, "a well-known expert in public policy", worked on an international project in south Asia on climate change, and spent a year in Pakistan before returning to India around 2012-13. She later took up a new job in 2015 and he too went to Pakistan once in 2013. He said the people of Assam had known these facts during the 11-year term of BJP-led Centre, which conducts background checks on opposition members, especially those like him who speak freely in Parliament. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Trade Bitcoin & Ethereum – No Wallet Needed! IC Markets Start Now Undo Sarma took to X to say Gogoi's "admission" that he did travel to Pakistan was just the tip of the iceberg of his links with the enemy country and his govt would reveal the full story through its investigative report on Sept 10. "Today he admitted (going to Pakistan) because he knows Sept 10 is approaching. But he has made a very false statement (that he went to visit his wife). It was an independent visit, approved by the Interior Department of Pakistan," he said. "What I will reveal on Sept 10 will make Rahul Gandhi regret appointing such a person to a leadership role," Sarma said, adding, "There are serious national security concerns at stake..." Gogoi said, "The CM has said he will make revelations on Sept 10. Is this a movie? This is a sensitive issue and he should reveal now what he has. BJP 's job is defamation and they are creating this whole thing like a C-grade Bollywood movie which will flop miserably." Sarma had written, "This is just the beginning, not the end. What lies ahead is far more serious. There exists every reasonable ground, supported by credible inputs and documented information, to suggest that Shri Gogoi has maintained proximity with the Pakistani establishment." He also alleged Gogoi's British wife was "snooping on our IB" on behalf of a climate activist group "and I have documents to prove that". Gogoi alleged the CM's "smear campaign" is a tactic to cover up the activities of his own family, adding he has amassed huge wealth and property through his family, which heads 17 companies and gets benefits of govt contracts. He further said illegal coal and drugs had emerged as the "biggest diseases" of northeast under BJP's patronage, and the reality of the region was far from the claims made during the "rising North East summit", which was addressed by PM Narendra Modi.

DMRC to take over desilting of covered Sunheri drain in S Delhi
DMRC to take over desilting of covered Sunheri drain in S Delhi

Time of India

timean hour ago

  • Time of India

DMRC to take over desilting of covered Sunheri drain in S Delhi

New Delhi: Post-monsoon, Delhi Metro Rail Corporation (DMRC) will take over the task of desilting the Sunheri drain in south Delhi. The work, to be carried out on behalf of Municipal Corporation of Delhi (MCD), will entail cutting a portion of the covered drain and opening the RCC deck slabs to create space for desilting. The 900-metre-long, 50-metre-wide drain, which passes through Dayal Singh College and Sunheri bus depot, has not been desilted since being covered in 2010, according to DMRC. The site frequently witnesses waterlogging, impacting nearby areas like Golf Links and Bharti Nagar. A DMRC official said the project, estimated to cost Rs 35 crore, is expected to be completed within a period of one year once work commences. "We were approached for desilting a portion of the covered Sunheri nullah. A tender has been floated and work will start after all requirements, such as award of tender, allotment of funds and mobilisation of the contractor, are finalised," he said, adding that the last date for filing applications is June 4. For the coming monsoon season, MCD will continue to be responsible for the desilting and ensuring there is no waterlogging. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Trade Bitcoin & Ethereum – No Wallet Needed! IC Markets Start Now Undo Sunehari nullah is a covered RCC box drain located at Lodhi Road. The project document states, "Its upstream end starts in Dayal Singh College premises and the downstream side ends in Sunehri bus depot at Lala Lajpat Rai flyover. There are five RCC boxes of width 10 m, and the depth varies from 3.5 m to 5.5 m. The drain was constructed in 2010, and it has not been desilted so far. The work includes desilting and cleaning of all five RCC box-covered drains. " The project will also entail making openings in the RCC boxes at suitable points for access and restoration. "A small portion of the RCC box drain (50 metres) will be taken out, followed by making a bund with sandbags at both ends to divert the flow of water. Dewatering will be done, making necessary ventilation arrangements, using a crane or cranes, expert manpower with proper safety equipment for removal of sludge, and its disposal," states the document. MCD had earlier informed NGT the project will be funded by NDMC. "DMRC is to carry out the modification in the covered portion of the Sunehri Pul drain and desilt it using appropriate methodology. The NDMC chairman has been formally requested to release the funds to DMRC," it told NGT, which is currently hearing the matter related to desilting of 24 major drains with outlets in the Yamuna.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store