A subgroup of the notorious Lazarus Group, backed by North Korea, has been discreetly establishing shell companies in the US, specifically in New York and New Mexico, as a means to infiltrate and compromise cryptocurrency developers, according to a report by Silent Push, a cybersecurity firm. The hackers, posing as US tech entrepreneurs, created two fictitious businesses, Blocknovas and Softglide, utilizing fake identities and addresses.

This operation marks a rare instance of North Korean hackers successfully setting up legitimate corporate entities in the US to create fronts for attacking unsuspecting job applicants. The hackers employ a manipulative yet effective strategy, utilizing fake professional profiles and job postings on platforms like LinkedIn to lure crypto developers into interviews, during which they are deceived into downloading malware disguised as job application tools. Silent Push has identified multiple victims of this operation, particularly those contacted through Blocknovas, which was found to be the most active of the front companies.

The malware used in this campaign includes at least three virus strains previously linked to North Korean cyber units, capable of stealing data, providing remote access to infected systems, and serving as entry points for additional spyware or ransomware. The FBI has seized the Blocknovas domain as part of a law enforcement action against North Korean cyber actors who used the domain to distribute malware and post fake job listings.