• bitcoinBitcoin (BTC) $ 80,247.00
  • ethereumEthereum (ETH) $ 2,285.57
  • tetherTether (USDT) $ 0.999597
  • bnbBNB (BNB) $ 674.16
  • xrpXRP (XRP) $ 1.44
  • usd-coinUSDC (USDC) $ 1.00
  • solanaSolana (SOL) $ 93.34
  • tronTRON (TRX) $ 0.350493
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.112211
  • whitebitWhiteBIT Coin (WBT) $ 59.00
  • usdsUSDS (USDS) $ 0.999672
  • cardanoCardano (ADA) $ 0.268620
  • hyperliquidHyperliquid (HYPE) $ 39.38
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.02
  • zcashZcash (ZEC) $ 553.01
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 436.54
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 10.36
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 406.32
  • canton-networkCanton (CC) $ 0.153201
  • the-open-networkToncoin (TON) $ 2.18
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.161735
  • suiSui (SUI) $ 1.23
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 57.83
  • usd1-wlfiUSD1 (USD1) $ 0.999343
  • daiDai (DAI) $ 0.999704
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.89
  • memecoreMemeCore (M) $ 3.18
  • hedera-hashgraphHedera (HBAR) $ 0.092780
  • wethWETH (WETH) $ 2,268.37
  • ethena-usdeEthena USDe (USDE) $ 0.999393
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007530
  • usdt0USDT0 (USDT0) $ 0.998824
  • global-dollarGlobal Dollar (USDG) $ 0.999748
  • paypal-usdPayPal USD (PYUSD) $ 0.999774
  • crypto-com-chainCronos (CRO) $ 0.078007
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 300.78
  • tether-goldTether Gold (XAUT) $ 4,681.67
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • uniswapUniswap (UNI) $ 3.70
  • polkadotPolkadot (DOT) $ 1.37
  • pax-goldPAX Gold (PAXG) $ 4,680.26
  • mantleMantle (MNT) $ 0.662797
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.066773
  • nearNEAR Protocol (NEAR) $ 1.60
  • ondo-financeOndo (ONDO) $ 0.391128
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • pi-networkPi Network (PI) $ 0.171216
  • okbOKB (OKB) $ 85.14
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • falcon-financeFalcon USD (USDF) $ 0.999304
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • internet-computerInternet Computer (ICP) $ 3.17
  • skySky (SKY) $ 0.074957
  • pepePepe (PEPE) $ 0.000004
  • aster-2Aster (ASTER) $ 0.669834
  • ripple-usdRipple USD (RLUSD) $ 0.999935
  • usddUSDD (USDD) $ 0.999725
  • aaveAave (AAVE) $ 96.79
  • ethereum-classicEthereum Classic (ETC) $ 9.36
  • bitget-tokenBitget Token (BGB) $ 2.06
  • bfusdBFUSD (BFUSD) $ 0.999200
  • morphoMorpho (MORPHO) $ 2.06
  • kucoin-sharesKuCoin (KCS) $ 8.32
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ethenaEthena (ENA) $ 0.119417
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • algorandAlgorand (ALGO) $ 0.119370
  • cosmosCosmos Hub (ATOM) $ 2.08
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.099343
  • quant-networkQuant (QNT) $ 72.61
  • kaspaKaspa (KAS) $ 0.037812
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • united-stablesUnited Stables (U) $ 0.999638
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • render-tokenRender (RENDER) $ 1.89
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.87
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.907972
  • worldcoin-wldWorldcoin (WLD) $ 0.269833
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 1.08
  • siren-2Siren (SIREN) $ 1.21
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.038576
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • arbitrumArbitrum (ARB) $ 0.136062
  • filecoinFilecoin (FIL) $ 1.07
  • gatechain-tokenGate (GT) $ 7.28
  • justJUST (JST) $ 0.090820
  • jupiter-exchange-solanaJupiter (JUP) $ 0.228174
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.008706
  • build-onBUILDon (B) $ 0.717959
  • pump-funPump.fun (PUMP) $ 0.001951
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • venice-tokenVenice Token (VVV) $ 14.64
  • vechainVeChain (VET) $ 0.007469
  • xdce-crowd-saleXDC Network (XDC) $ 0.032048
  • usdtbUSDtb (USDTB) $ 0.999271
  • beldexBeldex (BDX) $ 0.079880
  • bonkBonk (BONK) $ 0.000007
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • dexeDeXe (DEXE) $ 13.03
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ousgOUSG (OUSG) $ 115.22
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • ghoGHO (GHO) $ 0.999426
  • injective-protocolInjective (INJ) $ 5.85
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009213
  • clbtcclBTC (CLBTC) $ 76,920.00
  • dashDash (DASH) $ 44.84
  • official-trumpOfficial Trump (TRUMP) $ 2.36
  • usual-usdUsual USD (USD0) $ 0.998031
  • hash-2Provenance Blockchain (HASH) $ 0.010500
  • midnight-3Midnight (NIGHT) $ 0.033077
  • yldsYLDS (YLDS) $ 0.999809
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.797539
  • blockstackStacks (STX) $ 0.282202
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • a7a5A7A5 (A7A5) $ 0.012987
  • tbtctBTC (TBTC) $ 70,942.00
  • skyaiSkyAI (SKYAI) $ 0.499598
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.54
  • unibaseUnibase (UB) $ 0.202084
  • true-usdTrueUSD (TUSD) $ 0.999785
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000089
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.219705
  • billions-networkBillions Network (BILL) $ 0.195089
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • labLAB (LAB) $ 6.21
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • edgexedgeX (EDGE) $ 1.35
  • kite-2Kite (KITE) $ 0.208428
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • sei-networkSei (SEI) $ 0.068396
  • euro-coinEURC (EURC) $ 1.17
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • aerodrome-financeAerodrome Finance (AERO) $ 0.481241
  • chilizChiliz (CHZ) $ 0.043228
  • celestiaCelestia (TIA) $ 0.478999
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • humanityHumanity (H) $ 0.237205
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • adi-tokenADI (ADI) $ 4.03
  • usdgoUSDGO (USDGO) $ 0.999687
  • spx6900SPX6900 (SPX) $ 0.449153
  • tezosTezos (XTZ) $ 0.381372
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • curve-dao-tokenCurve DAO (CRV) $ 0.273518
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.18
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997520
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.408202
  • apxusdapxUSD (APXUSD) $ 0.999841
  • sun-tokenSun Token (SUN) $ 0.020084
  • usxUSX (USX) $ 0.999802
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ether-fiEther.fi (ETHFI) $ 0.451731
  • layerzeroLayerZero (ZRO) $ 1.47
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.069838
  • doublezeroDoubleZero (2Z) $ 0.103885
  • noonNoon (NOON) $ 0.751949
  • monadMonad (MON) $ 0.030166
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-goldKinesis Gold (KAU) $ 148.91
  • pendlePendle (PENDLE) $ 2.02
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • lido-daoLido DAO (LDO) $ 0.401714
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • flokiFLOKI (FLOKI) $ 0.000035
  • gnosisGnosis (GNO) $ 129.01
  • zebec-networkZebec Network (ZBCN) $ 0.003452
  • bitcoin-svBitcoin SV (BSV) $ 16.71
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

North Korean Hackers Try to Get Hired at Binance Every Day—Here’s How They’re Spotted

0 2


Every day, Binance is inundated with fake resumes that it’s certain were written by would-be North Korean attackers, the crypto exchange’s chief security officer Jimmy Su told Decrypt. In his view, nation-state actors from North Korea are the single largest threat facing companies in the crypto industry today.

Su explained that North Korean attackers have been an issue throughout the exchange’s eight-year existence, but recently, the hackers have upped their game when it comes to crypto.

“The largest vector currently against the crypto industry is state actors, particularly in the DPRK, [with] Lazarus,” Su told Decrypt, adding that, “They’ve had a crypto focus in the last two, three years and have been quite successful in their endeavors.” He added that “almost all the large DPRK hacks” have involved a fake employee helping facilitate the attack.

How North Korea attacks crypto exchanges

The Democratic People’s Republic of Korea, also referred to as the DPRK or North Korea, is home to the Lazarus Group, one of the most prolific hacker clans in the world. The group is believed to have been responsible for the infamous Bybit $1.4 billion hack in March—the largest hack in crypto history, according to the FBI.

Su said that Binance has mostly noticed North Korean attackers attempting to get hired at the firm. The centralized exchange claims to discard resumes daily, based on their tendency to use certain resume templates. The firm was not willing to share more specifics on resume red flags with Decrypt.

If those resumes make it past the initial vibe check, the company then must check that the applicant is legit on a video call—a challenge that is only getting harder with the rise of AI.

“Our tracking used to [show] that the actor, the operative, will have a resume, and they mostly either have a Japanese or Chinese surname,” Su explained. “But now, with AI and events in AI, they are able to fake to appear to be any kind of developer. More recently, we have seen them be candidates from Europe, from the Middle East. What they do is they actually use a voice changer during their interviews, and the video was a deepfake.”

“The only real good detection is that they almost always have a slow internet connection,” he added. “What’s happening is that the translation and the voice changer are working during the call … that’s why they are always delayed.”

There are other ways that Binance can detect a North Korean applicant—such as asking them to put their hand over their face, which usually breaks the deepfake—but Binance doesn’t want to reveal all of its tricks out of fear that attackers may be reading this article.

Other employers have been known to ask candidates to say something negative about North Korean supreme leader Kim Jong Un, which is believed to be outlawed in the country, and have reported positive results.

Binance claims to have never hired a nation-state actor; however, they can’t be too certain. As a result, they even monitor their current employees for suspicious behavior—something all financial institutions do to some degree.

Ironically, according to Su’s research, DPRK employees are usually among the company’s top performers in the given role. That’s likely because there may be multiple people doing the same job across multiple time zones, he explained. So Binance tracks when employees are working, along with their output.

If a worker doesn’t appear to ever sleep, it might be a sign they’re part of the infamous Lazarus Group.

How else is North Korea attacking?

There are two other frequent modes of attack employed by North Korean state actors, Su said. One involves poisoning public NPM libraries with malicious code, while the other sees the rogue state making fake job offers to crypto employees.

Node Package Manager (NPM) libraries, or packages, are collections of reusable code that developers will frequently use. Malicious attackers can duplicate these packages and insert a small line of code that could have grave consequences—all while maintaining its original function. If this is even picked up once, the malicious code will embed itself deeper and deeper into the system as developers build on top of it, Su said.

To prevent this from becoming an issue, Binance has to go through the code with a fine-tooth comb. Major crypto exchanges also share intelligence related to security in Telegram and Signal groups—meaning they’re able to flag poisoned libraries and emerging DPRK techniques with their peers.

“The DPRK group will [also] try to schedule calls with the external-facing employees,” Su told Decrypt. “Either as a DeFi project or investment firm. Worst yet, they’ll be recruiting them for a high-level job, paying twice, three times as much, just to get them onto an interview.”

During the fake interview, Su explained, the DPRK hackers will claim that the call has “some kind of video or voice issues,” before sending the victim a link to update their Zoom. Then, he said, their device is infected with malware.

Binance has trained its employees to report every phishing attempt made on them. By the frequency of these reports, Su is confident that DPRK attackers are messaging Binance employees on LinkedIn every day.

North Korean hackers stole $1.34 billion across 47 crypto-related incidents last year, a Chainalysis report revealed. Since then, the DPRK attacks have persisted, with Wiz’s Director of Strategic Threat Intelligence estimating that $1.6 billion in crypto has been stolen so far this year via fake IT job offers.

“Lazarus Group has always been an issue,” Su told Decrypt. “But in the last two, three years, they have switched their focus, more of their resources onto crypto. Just because of the industry’s [large] dollar amount.”



Source link

Leave A Reply

Your email address will not be published.