|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CoinDeskは最近、北朝鮮人がどのようにして業界に侵入したのかを詳述した調査結果を発表し、十数社の仮想通貨企業が

An extensive crypto investigation has uncovered a widespread infiltration by North Korean hackers, posing significant legal and cybersecurity risks for companies and investors in the industry.
暗号通貨の大規模な調査により、北朝鮮のハッカーによる広範な侵入が明らかになり、業界の企業や投資家に重大な法的およびサイバーセキュリティのリスクが生じています。
According to the report, over a dozen crypto companies have fallen victim to tactics employed by the Democratic People's Republic of Korea (DPRK) to circumvent sanctions and obtain funds from these projects.
報告書によると、制裁を回避してこれらのプロジェクトから資金を獲得するために朝鮮民主主義人民共和国(DPRK)が採用した戦術の犠牲になった仮想通貨企業は十数社あるという。
The investigation revealed that several companies, including prominent projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had unknowingly hired IT workers from the DPRK.
調査の結果、Fantom、Injective、Yearn Finance、ZeroLend、Sushi などの著名なプロジェクトを含むいくつかの企業が、知らずに北朝鮮から IT 労働者を雇用していたことが明らかになりました。
Interviews with founders, industry experts, and blockchain researchers during the investigation indicated that the infiltration was "far more prevalent" than initially suspected.
調査中の創業者、業界専門家、ブロックチェーン研究者へのインタビューでは、侵入が当初の予想よりも「はるかに蔓延している」ことが示された。
Most hiring management teams consulted during the investigation reported having interviewed and hired suspected DPRK developers or knew someone who had.
調査中に相談を受けた採用管理チームのほとんどは、北朝鮮の開発者と疑われる人物を面接して採用したことがある、あるいは採用した人物を知っていると報告した。
Blockchain developer Zaki Manian disclosed that he had unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain.
ブロックチェーン開発者のザキ・マニアン氏は、コスモス・ハブ・ブロックチェーンの開発を支援するために、2021年に知らずに北朝鮮のIT労働者2人を雇用していたことを明らかにした。
"Everyone is struggling to filter out these people," said Manian, adding that the probability of a job applicant being from the DPRK "is greater than 50% across the entire industry."
マニアン氏は「こうした人々を排除するのに誰もが苦労している」と述べ、求職者が北朝鮮出身である確率は「業界全体で50%を超えている」と付け加えた。
On-chain investigator ZachXBT had initially highlighted the North Korean chain of exploits in August, revealing that he had discovered over 25 crypto projects with DPRK-linked developers that had been active since June 2024.
オンチェーン調査員のZachXBT氏は8月に北朝鮮によるエクスプロイトの連鎖を当初強調し、2024年6月から活動していた北朝鮮関連の開発者との25以上の暗号プロジェクトを発見したことを明らかにした。
The crypto sleuth went on to reveal the names and addresses of 21 IT workers who had infiltrated the industry in just those three months.
暗号通貨探偵は続けて、わずか 3 か月の間に業界に侵入した 21 人の IT 従業員の名前と住所を明らかにしました。
"North Korea is receiving $300K – $500K / month from working at 25+ projects at once by using fake identities," ZachXBT stated.
ZachXBTは、「北朝鮮は、偽のIDを使用して25以上のプロジェクトに同時に取り組み、月に30万ドルから50万ドルを受け取っている」と述べた。
The report noted that North Korean cyberattacks "don't tend to resemble the Hollywood version of hacking." Instead, the hackers typically use some form of social engineering to gain the team's trust and ultimately obtain access to the project's private keys, often through a malicious link.
報告書は、北朝鮮のサイバー攻撃は「ハリウッド版のハッキングとは似ていない傾向がある」と指摘した。代わりに、ハッカーは通常、何らかの形式のソーシャル エンジニアリングを使用してチームの信頼を獲得し、最終的には悪意のあるリンクを通じてプロジェクトの秘密鍵へのアクセスを取得します。
"To date, we have never seen DPRK do, like, a real exploit. It's always social engineering, and then compromise the device, and then compromise the private keys," said Taylor Monian, Product Manager at MetaMask.
「これまでのところ、北朝鮮が実際のエクスプロイトなどを行っているのを見たことがありません。それは常にソーシャルエンジニアリングであり、その後デバイスを侵害し、その後秘密鍵を侵害します」とメタマスクのプロダクトマネージャー、テイラー・モニアン氏は述べた。
The North Korean developers often use fake documentation to disguise their nationality, as many countries prohibit hiring workers from the DPRK due to sanctions.
多くの国が制裁により北朝鮮からの労働者の雇用を禁止しているため、北朝鮮の開発業者は国籍を隠すために偽の書類を使用することが多い。
After being hired, the malicious actors initially perform well to gain their employers' trust. However, over time, inconsistencies in their work and story begin to emerge, leading the crypto companies to realize they have been targeted in a coordinated attack.
悪意のある攻撃者は、雇用された後、最初は雇用主の信頼を得るためにうまく機能します。しかし、時間が経つにつれて、彼らの仕事とストーリーに矛盾が現れ始め、仮想通貨企業は組織的な攻撃の標的にされたことに気づきます。
In some cases, teams have discovered that they were working with multiple individuals who presented as one person or that several of their employees were all the same person.
場合によっては、チームが 1 人の人物としてプレゼンテーションを行った複数の個人と作業していたり、複数の従業員がすべて同一人物であることに気付いたりすることがあります。
As reported by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this nature.
Bitcoinist が報告したように、イーサリアム レイヤー 2 NFT ゲーム プラットフォーム Munchables がこの種の攻撃の被害に遭いました。
In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.
3月には、開発者がハッカーに転向したことにより、プロジェクトは6,000万ドル以上の仮想通貨を失い、その後回収しました。
The heist was later revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government.
この強盗は後に内部犯行であることが明らかになり、ローラ・シン氏やザックXBT氏など複数の業界関係者が北朝鮮政府と関係していることが判明した。
Additionally, it was suspected that four of the developers in the team were all one person.
さらに、チームの開発者4人は全員1人である疑いもあった。
The investigation ultimately showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.
調査では最終的に、2021年のスシや、最近では2024年9月のデルタ・プライムなど、北朝鮮のIT労働者を雇用したいくつかの暗号プロジェクトが後にハッキングの被害に遭ったことが判明した。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































