Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Zefir Surpasses $530 Million in WhatsApp Revenue for Shopify Brands, Releases Benchmark Data on WhatsApp Automation Performance

September 26, 2026

Cathie Wood’s ARK teams with Securitize to tokenize venture fund with OpenAI, Anthropic stakes

September 26, 2026

Bitcoin – BTC to $300K? Fidelity says THIS level comes first

September 26, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Exploit Threat Intel Platforms For Phishing
North Korean Hackers Exploit Threat Intel Platforms For Phishing
Security and Privacy

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 4, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A coordinated effort by North Korea-aligned hackers to exploit cyber threat intelligence (CTI) platforms has been revealed by cybersecurity experts.

The investigation, uncovered by SentinelLabs and the internet intelligence company Validin, linked the activity to the Contagious Interview cluster, a campaign known for targeting job seekers with malware-laced recruitment lures.

Between March and June 2025, the group reportedly attempted to access Validin’s infrastructure intelligence portal, registering multiple accounts within hours of a blog post that detailed Lazarus-linked activity. The hackers used Gmail addresses previously associated with their operations, although Validin quickly blocked them. Despite this, they returned with new accounts, including domains registered specifically for the effort.

Persistent Attempts and Adaptation

The threat actors demonstrated persistence, repeatedly creating accounts and attempting logins over several months. SentinelLabs intentionally allowed one account to remain active to monitor their tactics. Investigators found evidence of team-based coordination, including the suspected use of Slack to share search results in real-time.

Instead of making broad infrastructure changes to avoid discovery, the hackers focused on deploying new systems to replace those taken down by service providers. This strategy enabled them to sustain a high tempo of victim engagement despite exposure.

Read more on Lazarus Group cyber operations: Over 200 Malicious Open Source Packages Traced to Lazarus Campaign

Infrastructure Scouting and OPSEC Failures

Researchers observed the group using Validin not only to track signs of detection but also to scout new infrastructure before purchase. Searches for recruitment-themed domains such as skillquestions[.]com and hiringassessment[.]net suggested efforts to avoid flagged assets.

Still, several operational security mistakes exposed log files and directory structures, offering rare insight into their workflows.

See also  WeMade Accused Of Fraud In The Latest Investigation Of The Korean Prosecutors

The investigation also revealed ContagiousDrop applications – malware delivery systems embedded in recruitment sites.

These applications sent email alerts when victims executed malicious commands and logged details such as names, phone numbers and IP addresses. More than 230 individuals, mainly in the cryptocurrency industry, were affected between January and March 2025.

Campaign Goals and Wider Impact

According to SentinelLabs, the Contagious Interview campaign primarily serves North Korea’s need for revenue, targeting cryptocurrency professionals worldwide through social engineering.

While the group has not adopted systematic measures to shield infrastructure, its resilience comes from rapid redeployment and continuous victim acquisition.

“Given the continuous success of their campaigns in engaging targets, it may be more pragmatic and efficient for the threat actors to deploy new infrastructure rather than maintain existing assets,” SentinelLabs explained.

The report emphasizes that vigilance from job seekers remains essential, especially in the cryptocurrency sector. Infrastructure providers also play a key role, as rapid takedowns significantly disrupt these operations.

Source link

exploit Hackers Intel Korean North Phishing Platforms threat
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Zano Inflation Bug Forces Blockchain to Wipe an Entire Day of History

September 26, 2026

Brooklyn man sent to prison for 12 years for stealing $16M in a Coinbase phishing scheme

September 25, 2026

White Hats Swipe $5.7M in NFTs Before Attackers Get Their Shot

September 25, 2026

Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund

September 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

TON Foundation Teams Up With HashKey to Drive Crypto On-Ramping in Telegram

April 12, 2024

‘Fuck regulators,’ said SBF behind closed doors: Report

October 31, 2023

HTX (formerly Huobi) Decides To Rebrand The HT Token But This Token Strangely Crashed By 22% 

January 20, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Zefir Surpasses $530 Million in WhatsApp Revenue for Shopify Brands, Releases Benchmark Data on WhatsApp Automation Performance

September 26, 2026

Cathie Wood’s ARK teams with Securitize to tokenize venture fund with OpenAI, Anthropic stakes

September 26, 2026

Bitcoin – BTC to $300K? Fidelity says THIS level comes first

September 26, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$84,290.000.47%
  • ethereumEthereum(ETH)$2,688.360.14%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$772.89-0.12%
  • rippleXRP(XRP)$1.52-2.03%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$121.550.16%
  • tronTRON(TRX)$0.334810-0.93%
  • zcashZcash(ZEC)$1,671.809.02%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.59%