- North Korean hackers reportedly stole $1.6 billion in cryptocurrencies by 2025, using fake job offers and sophisticated malware.
- The hacking groups, known as UNC4899, TraderTraitor, Jade Sleet, and Slow Pisces, targeted cloud systems of major crypto companies.
- These cybercriminals manipulated social media interactions to gain trust and access sensitive company information.
- Their attacks focused on companies utilizing cloud-first infrastructures like Google Cloud and AWS, leading to significant financial losses.
- A surge in fake IT job listings facilitated these breaches, particularly affecting cryptocurrency exchanges.
North Korean Hackers Exploit Crypto Sector with Fake Job Offers
In a staggering revelation from a Google Cloud report, North Korean hackers have escalated their attacks on the cryptocurrency industry in 2025. These cybercriminals stole over $1.6 billion using elaborate schemes involving fake job offers and cutting-edge malware. Particularly alarming is their method of gaining unauthorized access to cloud systems by posing as recruiters or experts in various fields.
The Rise of Sophisticated Cyber Threats
The group identified as UNC4899—or TraderTraitor among other aliases—has been under close watch for its advanced infiltration techniques. They primarily focus on building trust through social media before sending malicious scripts disguised as test assignments. This approach grants them remote access to company cloud environments where they can steal credentials and target nodes responsible for processing crypto transactions.
Targeting Cloud Infrastructures
Both Google Cloud and AWS have been victims of these sophisticated attacks which resulted in multi-million-dollar losses in cryptocurrencies. According to Jamie Collier from the Google Threat Intelligence Group, North Korean hackers frequently impersonate professionals such as journalists or professors to enhance credibility through AI-driven communication strategies.
Evolving Tactics: From JavaScript Attacks to IT Job Scams
TraderTraitor’s hacking campaigns began around 2020 with attacks through malicious crypto applications built on JavaScript (Electron). By 2024-2025, their tactics evolved into mass phishing via fake IT job listings—a strategy that heavily targeted cryptocurrency exchanges.
Major Heists Shake Crypto Markets
Some of the most notable breaches include a $303 million hack of Japan’s DMM Bitcoin exchange and a colossal $1.5 billion theft from Bybit reported in early 2025. Benjamin Read from Wiz highlights that TraderTraitor’s focus on cloud-based attacks stems from the industry’s reliance on cloud-first infrastructures—where data equates to money.
Growing Threat Landscape
Estimates suggest thousands may be involved with TraderTraitor across interconnected hacker groups. TRM Labs previously reported over $2.1 billion lost in the crypto sector during the first half of 2025 alone. Google’s warning about expanding North Korean hacker activities underscores an urgent need for heightened cybersecurity measures across the industry.
The persistent evolution of these threats presents significant challenges but also opportunities for innovation within cybersecurity practices tailored specifically toward safeguarding digital assets against increasingly sophisticated adversaries.
