Multiple North Korean-linked threat groups have been actively targeting organizations and individuals in the Web3 and cryptocurrency space, according to Mandiant’s M-Trends 2025 report. These financially motivated attacks appear designed to circumvent international sanctions and generate funds for North Korea’s weapons programs.
“These activities aim to generate financial gains, reportedly funding North Korea’s weapons of mass destruction program and other strategic assets,” Mandiant researchers noted.
## Sophisticated Threat Clusters
The cybersecurity firm identified several threat actors using custom tools written in Golang, C++, and Rust that can infect Windows, Linux, and macOS systems:
– **UNC1069** (active since 2018): Targets various industries using social engineering, including fake meeting invites and posing as investors on Telegram to access digital assets.
– **UNC4899** (active since 2022): Orchestrates job-themed campaigns delivering malware disguised as coding assignments and has conducted supply chain compromises.
– **UNC5342** (active since 2022): Employs job-related lures to trick developers into running malicious projects.
– **UNC4736**: Targets the blockchain industry by trojanizing trading software, linked to the 2023 3CX supply chain attack.
– **UNC3782**: Conducts large-scale phishing campaigns against cryptocurrency users, transferring over $137 million in assets in a single day during a 2023 operation targeting TRON users.
## IT Worker Infiltration Scheme
Since 2022, North Korea has deployed thousands of IT workers (tracked as UNC5267) to secure remote employment at companies across the U.S., Europe, and Asia while primarily residing in China and Russia. Many are affiliated with the 313 General Bureau responsible for North Korea’s nuclear program.
These workers use stolen identities, fabricated personas, and real-time deepfake technology during job interviews to avoid detection. This approach allows:
– A single operator to interview multiple times using different synthetic identities
– Operatives to avoid identification in security bulletins
– Enhanced operational security with decreased detectability
“In 2024, Mandiant identified a suspected DPRK IT worker using at least 12 personas while seeking employment in the U.S. and Europe,” the report stated. In one case, “four suspected DPRK IT workers had been employed within a 12-month period at a single organization.”
These infiltration tactics enable North Korea to funnel salaries back to Pyongyang, maintain long-term access to victim networks, and potentially extort employers while facilitating data theft and cyberattacks.
