- Lazarus Group registered fictitious US companies to distribute malware to crypto developers under the guise of job recruitment.
- Malware was embedded in coding tests sent through legitimate platforms, such as LinkedIn, Upwork and Telegram.
- US authorities confirm the campaign is linked to North Korea’s broader effort to fund its sanctioned weapons program.
North Korean hackers created fictitious US firms to deploy malware-laced job offers in corporate espionage campaigns, according to Reuters.
Lazarus used fake firms to launch malware attacks on crypto developers
The Lazarus Group, North Korea’s state-backed cyber unit, has established multiple fake companies registered in the United States to lure blockchain developers into downloading malware, according to a recent FBI-supported investigation.
Entities such as Blocknovas LLC and Softglide LLC, registered in New Mexico and New York, respectively, served as the primary fronts for the operation. Researchers at cybersecurity firm Silent Push confirmed the companies were incorporated using fabricated identities and fake addresses, complete with professional websites and job listings on platforms like LinkedIn and Upwork.
The malicious campaign targeted software engineers in the crypto and Web3 space. Once applicants engaged with the fake recruiters, they were invited to fake interviews and sent “test assignments.” These files contained embedded malware designed to extract browser credentials, private keys and wallet access details from the victim’s device.
“It is the first confirmed case of North Korean actors incorporating US entities to gain operational legitimacy,” said Kasey Best, Director of Threat Intelligence at Silent Push.
According to Reuters, the operation was uncovered when Silent Push identified connections between the front companies’ digital infrastructure and previously known Lazarus malware strains.
The Federal Bureau of Investigation (FBI) has since seized the domain for Blocknovas as part of an active enforcement effort against North Korean cyber actors.
Crypto theft financing North Korean espionage and missile efforts
Investigators estimate that hundreds of developers were targeted by the operation, with some infections leading to more than financial loss. Evidence suggests that access gained through these malware implants may have been escalated to other state-aligned DPRK teams for potential espionage use.
“Our efforts focus on imposing consequences not only on DPRK actors but on anyone facilitating their ability to conduct these schemes,” said a senior FBI official in a statement.
US and South Korean intelligence agencies believe thousands of North Korean IT workers operate globally, often under false identities, to generate capital for Pyongyang’s weapons development. A 2023 United Nations report estimated that North Korea’s cybercrime earnings contribute directly to its nuclear missile program.
Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers. The author will not be held responsible for information that is found at the end of links posted on this page.
If not otherwise explicitly mentioned in the body of the article, at the time of writing, the author has no position in any stock mentioned in this article and no business relationship with any company mentioned. The author has not received compensation for writing this article, other than from FXStreet.
FXStreet and the author do not provide personalized recommendations. The author makes no representations as to the accuracy, completeness, or suitability of this information. FXStreet and the author will not be liable for any errors, omissions or any losses, injuries or damages arising from this information and its display or use. Errors and omissions excepted.
The author and FXStreet are not registered investment advisors and nothing in this article is intended to be investment advice.
Recommended Content
Editors’ Picks

Is Ethereum's comeback real?
Ethereum price hovers above $2,500 on Friday after soaring nearly 100% since early April's bottom. The ETH Pectra upgrade has boosted over 11,000 EIP-7702 authorizations in a week, indicating healthy uptake by wallets and dApps. The growing stablecoin usage and tokenization, Layer 2 institutionalization and ETH short unwind support the price rally.

Bitcoin Weekly Forecast: BTC stabilizes near $103,000 amid trade optimism, rising institutional demand
Bitcoin price stabilizes around $103,000 on Friday after facing multiple rejections at the key $105,000 resistance level throughout the week. Risk-on sentiment prevails, driven by global trade deals, strong corporate accumulation, and spot ETF inflows.

EOS price climbs as sentiment improves following $3 million purchase by President Trump's World Liberty Financial
EOS price rebounds from short-term support at $0.75, boosting bullish sentiment amid broader market consolidation. President Donald Trump's World Liberty Financial purchases $3 million worth of EOS at an average price of $0.82.

FTX creditors set to receive over $5 billion in recovery plan payout handled by Kraken and BitGo
Defunct crypto exchange FTX will distribute $5 billion to holders of allowed claims starting May 30. Creditors with completed pre-distribution requirements will receive between 54% and 120% of their original claims.

Bitcoin: BTC stabilizes near $103,000 amid trade optimism, rising institutional demand
Bitcoin (BTC) price stabilizes at around $103,000 when writing on Friday, after facing multiple rejections at the key $105,000 resistance level throughout the week.