|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CoinDesk는 최근 북한 사람들이 업계에 어떻게 침투했는지 자세히 조사한 결과를 발표했습니다.

An extensive crypto investigation has uncovered a widespread infiltration by North Korean hackers, posing significant legal and cybersecurity risks for companies and investors in the industry.
광범위한 암호화폐 조사를 통해 북한 해커의 광범위한 침투가 밝혀졌으며, 이는 업계 기업과 투자자에게 심각한 법적 및 사이버 보안 위험을 초래합니다.
According to the report, over a dozen crypto companies have fallen victim to tactics employed by the Democratic People's Republic of Korea (DPRK) to circumvent sanctions and obtain funds from these projects.
보고서에 따르면, 12개 이상의 암호화폐 회사가 제재를 회피하고 이러한 프로젝트에서 자금을 얻기 위해 조선민주주의인민공화국(북한)이 사용한 전술의 희생양이 되었습니다.
The investigation revealed that several companies, including prominent projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had unknowingly hired IT workers from the DPRK.
조사 결과 Fantom, Injective, Yearn Finance, ZeroLend, Sushi 등 유명 프로젝트를 포함한 여러 기업이 자신도 모르게 북한에서 IT 인력을 고용한 것으로 드러났습니다.
Interviews with founders, industry experts, and blockchain researchers during the investigation indicated that the infiltration was "far more prevalent" than initially suspected.
조사 중 창립자, 업계 전문가 및 블록체인 연구원과의 인터뷰에서는 침입이 처음에 의심했던 것보다 "훨씬 더 널리 퍼졌다"는 사실이 나타났습니다.
Most hiring management teams consulted during the investigation reported having interviewed and hired suspected DPRK developers or knew someone who had.
조사 과정에서 협의한 대부분의 채용 관리팀은 북한 개발자로 의심되는 사람을 인터뷰하고 채용했거나 그런 사람을 알고 있다고 보고했습니다.
Blockchain developer Zaki Manian disclosed that he had unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain.
블록체인 개발자인 자키 매니안(Zaki Manian)은 코스모스 허브 블록체인 개발을 돕기 위해 자신도 모르게 2021년에 북한 IT 직원 2명을 고용했다고 밝혔습니다.
"Everyone is struggling to filter out these people," said Manian, adding that the probability of a job applicant being from the DPRK "is greater than 50% across the entire industry."
매니안은 "모든 사람이 이런 사람들을 걸러내려고 애쓰고 있다"고 말하며 구직자가 북한 출신일 확률은 "전체 업계에서 50% 이상"이라고 덧붙였다.
On-chain investigator ZachXBT had initially highlighted the North Korean chain of exploits in August, revealing that he had discovered over 25 crypto projects with DPRK-linked developers that had been active since June 2024.
온체인 조사관 ZachXBT는 지난 8월 처음으로 북한의 일련의 공격을 강조하면서 2024년 6월부터 활동해온 북한 관련 개발자들과 함께 25개 이상의 암호화폐 프로젝트를 발견했다고 밝혔습니다.
The crypto sleuth went on to reveal the names and addresses of 21 IT workers who had infiltrated the industry in just those three months.
암호화폐 수사관은 단 3개월 만에 업계에 침투한 IT 직원 21명의 이름과 주소를 공개했습니다.
"North Korea is receiving $300K – $500K / month from working at 25+ projects at once by using fake identities," ZachXBT stated.
ZachXBT는 "북한은 가짜 신분을 사용하여 동시에 25개 이상의 프로젝트를 진행함으로써 월 30만~50만 달러를 받고 있다"고 밝혔습니다.
The report noted that North Korean cyberattacks "don't tend to resemble the Hollywood version of hacking." Instead, the hackers typically use some form of social engineering to gain the team's trust and ultimately obtain access to the project's private keys, often through a malicious link.
보고서는 북한의 사이버 공격이 "할리우드 버전의 해킹과 유사한 경향이 없다"고 지적했습니다. 대신 해커는 일반적으로 일종의 사회 공학을 사용하여 팀의 신뢰를 얻고 궁극적으로 악의적인 링크를 통해 프로젝트의 개인 키에 대한 액세스 권한을 얻습니다.
"To date, we have never seen DPRK do, like, a real exploit. It's always social engineering, and then compromise the device, and then compromise the private keys," said Taylor Monian, Product Manager at MetaMask.
MetaMask의 제품 관리자인 Taylor Monian은 "지금까지 북한이 실제 공격을 하는 것을 본 적이 없습니다. 이는 항상 사회 공학적이며 장치를 손상시키고 개인 키를 손상시키는 것입니다."라고 말했습니다.
The North Korean developers often use fake documentation to disguise their nationality, as many countries prohibit hiring workers from the DPRK due to sanctions.
많은 국가에서 제재로 인해 북한 근로자 채용을 금지하고 있기 때문에 북한 개발자들은 종종 가짜 문서를 사용하여 국적을 위장합니다.
After being hired, the malicious actors initially perform well to gain their employers' trust. However, over time, inconsistencies in their work and story begin to emerge, leading the crypto companies to realize they have been targeted in a coordinated attack.
악의적인 공격자는 고용된 후 처음에는 좋은 성과를 거두어 고용주의 신뢰를 얻습니다. 그러나 시간이 지남에 따라 작업과 이야기에 불일치가 나타나기 시작하여 암호화폐 회사는 조직화된 공격의 표적이 되었음을 깨닫게 됩니다.
In some cases, teams have discovered that they were working with multiple individuals who presented as one person or that several of their employees were all the same person.
어떤 경우에는 팀에서 한 사람으로 표현된 여러 개인과 작업하고 있거나 직원 중 여러 명이 모두 같은 사람이라는 사실을 발견했습니다.
As reported by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this nature.
Bitcoinist가 보고한 바와 같이 Ethereum Layer-2 NFT 게임 플랫폼 Munchables는 이러한 공격의 희생양이 되었습니다.
In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.
지난 3월, 개발자가 해커로 변신한 후 프로젝트는 6천만 달러 이상의 암호화폐를 잃었다가 나중에 복구했습니다.
The heist was later revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government.
이 강도 사건은 나중에 내부 소행으로 밝혀졌으며 Laura Shin 및 ZachXBT와 같은 업계 인사들에 의해 북한 정부와 연결되었습니다.
Additionally, it was suspected that four of the developers in the team were all one person.
게다가 팀 내 개발자 4명이 모두 1명인 것으로 의심됐다.
The investigation ultimately showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.
조사 결과, 2021년 스시(Sushi), 가장 최근에는 2024년 9월 델타 프라임(Delta Primes)을 포함해 나중에 북한 IT 직원을 고용한 여러 암호화폐 프로젝트가 해킹의 희생양이 된 것으로 나타났습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































