Kraken Exposes North Korean Hacker Posing as Job Candidate in Bold Infiltration Attempt
By: beincrypto|2025/05/02 20:00:04
0
Share
Kraken, a prominent cryptocurrency exchange, has uncovered a sophisticated infiltration attempt by a North Korean hacker posing as a job candidate. The security and recruitment teams advanced the candidate through the hiring process. The aim was to study their strategies and gather crucial insights. How a North Korean Hacker Tried to Infiltrate KrakenKraken detailed the incident in a recent blog post on May 1. The hacker applied for an engineering role at the exchange, initially appearing as a legitimate candidate, allegedly named Steven Smith. However, several red flags emerged during the hiring process. “What started as a routine hiring process for an engineering role quickly turned into an intelligence gathering operation, as our teams carefully advanced the candidate through our hiring process to learn more about their tactics at every stage of the process,” Kraken noted.The candidate used a different name during the interview and kept switching voices, suggesting coaching. They applied using an email linked to North Korean hackers. Moreover, the Open-Source Intelligence gathering (OSINT) investigation uncovered the candidate’s involvement in a network of fake identities.“This meant that our team had uncovered a hacking operation where one individual had established multiple identities to apply for roles in the crypto space and beyond. Several of the names had previously been hired by multiple companies, as our team identified work-related email addresses linked to them. One identity in this network was also a known foreign agent on the sanctions list,” the blog read.Additionally, technical inconsistencies in their setup, like using remote, colocated Mac desktops accessed via a VPN and altered IDs, pointed to an infiltration attempt. This information confirmed that the candidate was likely a state-sponsored hacker.In a final interview with the candidate, Kraken’s Chief Security Officer, Nick Percoco, and some team members confirmed the company’s suspicions. The candidate’s failure to verify their location or answer questions about their city and citizenship revealed them as an impostor.“Their job is to start employment to steal intellectual property, steal money from those companies, take home a paycheck, and do it in a widespread way,” Percoco told CBS about the hackers.FinCEN Proposes Ban on Huione Group Over North Korean Ties Meanwhile, in another development, the US Financial Crimes Enforcement Network (FinCEN) has proposed banning Cambodia-based Huione Group from the US financial system. The department identified Huione as a key facilitator for North Korean hacker groups, including those involved in cyber heists and “pig butchering” cryptocurrency scams.“Huione Group has established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans,” Secretary of the Treasury Scott Bessent said.FinCEN accused the group of laundering over $4 billion in illicit funds between August 2021 and January 2025. According to the department, Huione’s network, including Huione Pay, Huione Crypto, and Haowang Guarantee, is a preferred marketplace for cryptocurrency criminals, offering services such as payment processing and an illicit online marketplace.“Today’s proposed action will sever Huione Group’s access to correspondent banking, degrading these groups’ ability to launder their ill-gotten gains. Treasury remains committed to disrupting any attempt by malicious cyber actors to secure revenue from or for their criminal schemes,” Bessent added.These incidents highlighted a pattern of North Korean cyberattacks on the cryptocurrency sector. In 2024, hackers stole over $659 million from crypto firms. According to a joint statement from the United States, Japan, and the Republic of Korea, North Korean hackers targeted the industry using tactics like social engineering and malware (e.g., TraderTraitor, AppleJeus). Additionally, North Korean IT workers were identified as insider threats to private sector companies.Previously, BeInCrypto reports have highlighted the notorious Lazarus Group, a North Korean state-sponsored hacking collective’s involvement in Bybit and Upbit thefts. Moreover, hacker groups from the country were also behind the Radiant Capital hack and the DMM Bitcoin exploit.In fact, recently, on-chain investigator ZachXBT uncovered significant North Korean involvement in decentralized finance (DeFi) protocols, with some of them relying on nearly 100% of their monthly volume/fees from the Democratic People’s Republic of Korea (DPRK).The post Kraken Exposes North Korean Hacker Posing as Job Candidate in Bold Infiltration Attempt appeared first on BeInCrypto.
You may also like

The pricing controversy of Trade.xyz exposes the fatal weakness of Pre-IPO perpetual contracts
SpaceX's equity update has sparked controversy over on-chain liquidations. Trade.xyz refuses to reset the SPCX pricing, and the lack of a Rebase mechanism in Perp DEX has led to a significant trust test for on-chain Pre-IPO assets.

World Cup 2026 Coming – WEEX Celebrates with $1M Prize Pool & Michael Owen Live
The 2026 FIFA World Cup is hours away. WEEX unveils the “World Cup x Dice Rush” campaign with a 1,000,000 USDT prize pool. Plus, Michael Owen reunites with WEEX COO for an exclusive pre-match livestream. Join now!

Galaxy in-depth report: Is Solana still worth paying attention to?
Solana did not fall behind during the bear market. Trading enthusiasm has waned, but the network is more stable, RWA and stablecoins are expanding, and the capital foundation is much thicker than in the previous cycle. The real question is: when the speculative tide recedes, can perpetuals, predicti...

Young people in South Korea make a "final effort" in the epic bull market
The South Koreans' average of two accounts for wildly gambling in the chip bull market reflects the survival anxiety and harsh reality of countless young people trying to break through class barriers behind the nationwide stock trading frenzy for wealth.

Dialogue with OmenX Founder: Why does the prediction market need an evolution from "spot" to "derivatives"?
How to reconstruct the prediction market using leverage?

When the P2P illicit funds from ten years ago turned into 60,000 bitcoins
The largest Bitcoin money laundering case in the UK has new developments: 16,000 Chinese victims are pursuing 61,000 seized Bitcoins across borders, and the dispute over the applicability of UK and Chinese laws will directly determine whether the victims can share in the soaring profits.

Morning News | CME Group launches Nasdaq Cryptocurrency Index futures; Asset management giant Janus Henderson strategically invests in Ethena
Overview of Important Market Events on June 10

Why did Oracle deliver the strongest financial report in history, yet its stock price fell?
Oracle's revenue for fiscal year 2026 set a record, with AI cloud orders soaring to $638 billion, but massive capital expenditures on computing power led to negative free cash flow, causing a 5% drop in after-hours stock prices.

Bitcoin Layer 2 Network Botanix: Why Did We Choose to Dissolve?
The Bitcoin L2 star project Botanix announced a gradual shutdown, with the team admitting to facing severe challenges from the failure of its business model and the prevailing trends. Users are urged to withdraw all assets before July 9, 2026.

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing
Overview of Important Market Events on June 9th

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?
The platform that wins this competition will be the one whose execution layer is the hardest to replicate, whose builder ecosystem delivers the fastest, and whose regulatory path is the most open.

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI
The combination of AI and crypto is still in its early stages, with both serving as complementary "middleware": AI translates human intentions into executable programs, while cryptographic technology provides verifiable and tamper-proof guarantees for computational processes and results. In the dire...

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention
Instead of competing with ambition, focusing on restraint, how does Anthropic leverage extreme strategic focus and an "counterintuitive" geek culture to counterattack OpenAI on the AI battlefield?

Every exchange is a "Universal Exchange."
You initially build infrastructure for something, then realize it can also be used for many other things, and then you continuously expand the business to accommodate everything that the infrastructure can support.

The counterattack of traditional finance: Alliance chains are quietly reviving
Whether public chains win or consortium chains win has never been the focus.

Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?
Top tech companies are going public later and later, leaving retail investors shut out during the high growth period. Can tokenization give ordinary people back this entry ticket?

Mastercard Launches Agent Pay for AI, Plans to Record AI Agent Payment Authorizations on Polygon
Mastercard launched Agent Pay for AI, a new payment protocol designed to help AI agents make small payments such as pay-per-use access to data and APIs. The system plans to record human-granted AI agent permissions on Polygon, focusing on verifiable authorization, identity, and payment controls.

Curve Deploys Llamalend v2 on Optimism With 250,000 OP Incentives
Curve launched Llamalend v2 on Optimism with 250,000 OP incentives from the Optimism Foundation. The upgrade expands Llamalend beyond its earlier crvUSD-focused model, adding broader collateral support, LlamaRisk market reviews, and the ability to use Curve LP tokens as collateral.
The pricing controversy of Trade.xyz exposes the fatal weakness of Pre-IPO perpetual contracts
SpaceX's equity update has sparked controversy over on-chain liquidations. Trade.xyz refuses to reset the SPCX pricing, and the lack of a Rebase mechanism in Perp DEX has led to a significant trust test for on-chain Pre-IPO assets.
World Cup 2026 Coming – WEEX Celebrates with $1M Prize Pool & Michael Owen Live
The 2026 FIFA World Cup is hours away. WEEX unveils the “World Cup x Dice Rush” campaign with a 1,000,000 USDT prize pool. Plus, Michael Owen reunites with WEEX COO for an exclusive pre-match livestream. Join now!
Galaxy in-depth report: Is Solana still worth paying attention to?
Solana did not fall behind during the bear market. Trading enthusiasm has waned, but the network is more stable, RWA and stablecoins are expanding, and the capital foundation is much thicker than in the previous cycle. The real question is: when the speculative tide recedes, can perpetuals, predicti...
Young people in South Korea make a "final effort" in the epic bull market
The South Koreans' average of two accounts for wildly gambling in the chip bull market reflects the survival anxiety and harsh reality of countless young people trying to break through class barriers behind the nationwide stock trading frenzy for wealth.
Dialogue with OmenX Founder: Why does the prediction market need an evolution from "spot" to "derivatives"?
How to reconstruct the prediction market using leverage?
When the P2P illicit funds from ten years ago turned into 60,000 bitcoins
The largest Bitcoin money laundering case in the UK has new developments: 16,000 Chinese victims are pursuing 61,000 seized Bitcoins across borders, and the dispute over the applicability of UK and Chinese laws will directly determine whether the victims can share in the soaring profits.
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com



