<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[North Korea&#x27;s Hackers Have Evolved From Phishing to Physical Infiltration]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1778647983732-5d6504c6-b0fc-4987-a0c1-18503fbab48f-image.png" alt="5d6504c6-b0fc-4987-a0c1-18503fbab48f-image.png" class=" img-fluid img-markdown" /><br />
CertiK's report traces a clear tactical evolution in DPRK-linked crypto operations that culminates in something genuinely alarming: physical infiltration of target organizations. The progression moves from early phishing and social engineering — including the Ronin Bridge exploit in 2022, attributed to a spearphishing campaign involving a fake LinkedIn recruiter and a malware-laden PDF — through increasingly sophisticated supply chain compromises like Bybit, and into what CertiK calls "physical infiltration," illustrated by the April 2026 Drift Protocol incident. In that case, approximately $285 million was drained from the Solana-based platform after a six-month operation involving conference attendance, relationship-building across the industry, and governance manipulation — meaning North Korean operatives spent half a year establishing trusted relationships before executing the actual exploit. CertiK blockchain intelligence analyst Jonathan Riss told Cointelegraph that DPRK-linked operations now blend intelligence tradecraft with technical exploits, and that North Korean IT workers and intermediaries can obtain trusted roles inside Western crypto and fintech firms under false identities.</p>
<p dir="auto">The practical implication for crypto organizations is that the threat model has expanded beyond technical security into personnel security and organizational trust. A firm with perfectly hardened smart contracts, robust key management, and comprehensive phishing training is still vulnerable if a DPRK operative has spent six months building relationships with governance participants and developers under a false identity. That is not a problem that any amount of code auditing solves — it requires identity verification processes, background screening, and operational security practices around sensitive roles that the crypto industry has historically treated as unnecessary overhead. The elevation of this issue from a cybersecurity concern to an international security matter, as cited UN and US intelligence assessments in CertiK's report confirm, means that the regulatory and law enforcement response will eventually catch up — but in the meantime, the industry is facing a state-level adversary that has explicitly allocated significant national resources to crypto theft as a revenue strategy.</p>
]]></description><link>https://undeads.com/forum/topic/19875/north-korea-s-hackers-have-evolved-from-phishing-to-physical-infiltration</link><generator>RSS for Node</generator><lastBuildDate>Fri, 19 Jun 2026 18:53:53 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/19875.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 04:53:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to North Korea&#x27;s Hackers Have Evolved From Phishing to Physical Infiltration on Wed, 13 May 2026 07:42:24 GMT]]></title><description><![CDATA[<p dir="auto">Trust no one.</p>
]]></description><link>https://undeads.com/forum/post/55473</link><guid isPermaLink="true">https://undeads.com/forum/post/55473</guid><dc:creator><![CDATA[JanEmil]]></dc:creator><pubDate>Wed, 13 May 2026 07:42:24 GMT</pubDate></item><item><title><![CDATA[Reply to North Korea&#x27;s Hackers Have Evolved From Phishing to Physical Infiltration on Wed, 13 May 2026 07:22:56 GMT]]></title><description><![CDATA[<p dir="auto">State level adversary with national resources targeting your governance participants, threat model got significantly more serious</p>
]]></description><link>https://undeads.com/forum/post/55472</link><guid isPermaLink="true">https://undeads.com/forum/post/55472</guid><dc:creator><![CDATA[lingriiddd]]></dc:creator><pubDate>Wed, 13 May 2026 07:22:56 GMT</pubDate></item><item><title><![CDATA[Reply to North Korea&#x27;s Hackers Have Evolved From Phishing to Physical Infiltration on Wed, 13 May 2026 07:22:45 GMT]]></title><description><![CDATA[<p dir="auto">North Korean operatives spent six months at crypto conferences making friends before stealing $285M, most patient heist ever</p>
]]></description><link>https://undeads.com/forum/post/55471</link><guid isPermaLink="true">https://undeads.com/forum/post/55471</guid><dc:creator><![CDATA[lingriiddd]]></dc:creator><pubDate>Wed, 13 May 2026 07:22:45 GMT</pubDate></item></channel></rss>