North Korean Hackers Set Up Fake U.S. Firms to Target Crypto Devs

Krutika Adani

Crypto Devs Targeted by Fake U.S. Companies

North Korea’s Lazarus Group created three fake firms—including two U.S.-registered LLCs—to spread malware in the crypto industry.

The Shell Companies Behind the Scam

  • BlockNovas LLC (New Mexico)

  • SoftGlide LLC (New York)

  • Angeloper Agency (unregistered)

  • All part of a malware campaign called “Contagious Interview.”

Job Interviews as the Bait

Hackers used fake job interviews to infect developers’ systems, aiming to steal wallets and credentials and infiltrate legitimate companies.

AI-Generated Identities & Fake Domains

To appear legit, they used AI-made employee profiles and domains like blocknovas[.]com—making the operation nearly indistinguishable from the real deal.

Lazarus Group: $3B+ in Crypto Stolen

From the Axie Infinity hack ($625M) to this new scheme, Lazarus continues to weaponize trust to steal billions from the crypto world.

Know more