ZachXBT:先潜伏再攻击 起底朝鲜加密黑客不为人知的幕后

币界网Published on 2024-08-16Last updated on 2024-08-16

币界网报道:

作者:ZachXBT,加密侦探;翻译:xiaozou

最近有一个团队寻求我的帮助,事情的起因是有人通过恶意代码从他们的金库中盗走130万美元。

这个团队不知道的是,他们雇佣了多名虚假身份的朝鲜IT人员作为开发者。

然后,我发现了自2024年6月以来与这些开发人员有关的一直保持活跃的加密项目就有至少25个。

Ug98A5k43OCadR6PV9T0zhg4tDibQ4vgVp2hYpiD.jpeg

lheEauB1zFVBuxvxomKNT3qSLLbwsu5cSf0qIMru.jpeg

该事件的洗钱途径如下:

1)将130万美元转移到偷盗地址

2)通过deBridge将130万美元从Solana桥接到以太坊

3)向Tornado存入50.2 ETH

4)向两个交易所转账16.5 ETH

偷盗地址为:

6USfQ9BX33LNvuR44TXr8XKzyEgervPcF4QtZZfWMnet

wa4FN9wAIQ1HWVh33aZQKEdnpZpeDihbIfujeQPi.jpeg

借助21个开发者的多个支付地址,我能够绘制出过去的一个月里最近一批约37.5万美元的支付集群。

0 xb721adfc3d9fe01e9b3332183665a503447b1d35

在过去的一周里,你可能也看到了,我请这些项目直接联系我。

7cqfs8eklzljoFc5aHxPxPlpD3wPP4jubNlGZc22.jpeg

此前,有550万美元流入了一个外汇存款地址,其中包括朝鲜IT人员从2023年7月至2024年期间收到的款项,该地址与OFAC制裁人员Sim Hyon Sop有关。

0x8f0212b1a77af1573c6ccdd8775ac3fd09acf014

Wm80X7J0bQ3g0Vu1oFT7vzumduQZpEFNktPyCx71.png

i9P8peI90OwREY5xJvm9U3o5ULy1DTHKsO0TubZT.jpeg

pTUi5j1PHLY3Zv3UZlErAePi9MWQ0ilDDWEZjGOY.png

调查过程中发现了一些有趣的事:

- 俄罗斯电信IP被美国和马来西亚的开发者使用。

- 在开发记录中他们不小心泄露了他们在记事本上的其他身份。

- 开发付款地址涉及到OFAC制裁名单上的Sang Man Kim和Sim Hyon Sop的。

- 一些开发者是由招聘公司安排的。

- 多个项目具有3名以上互推荐IT人员。

hTwIvN5rUdqpepL36WaP5GuFCSQ4vuFnf5jxXyXF.jpeg

LN6PpgWo1q6eNQbKfdOKYyHC9MP4FVjCIKT2ywjb.jpeg

许多经验丰富的团队都雇佣了这些开发者,所以把他们当成是罪魁祸首是不公平的。

各团队未来可以关注的一些指标包括:

1) 他们互推荐的角色

2) 漂亮的简历/ GitHub活动,尽管有时会谎报工作经历。

3) 通常表面上乐意接受KYC,但却提交假身份证,希望团队不会进一步调查。

4) 关于他们所声称的来源地,问些具体问题。

5) 一个开发人员被解雇了,但立即出现了好几个找工作的新账户。

6) 可能一眼看起来是很优秀的开发者,但往往工作起来就表现不佳。

7) 查看日志

8) 喜欢使用流行NFT pfps

9) 亚洲口音

以防你是那种把一切归咎于朝鲜的事都称为巨大阴谋的人。

无论如何,这项研究证明:

在亚洲,一个实体通过使用假身份可以同时从事25个以上的项目,每月可以获得30万至50万美元的收入。

后续:

在本文发布不久后,另一个项目发现他们雇佣了我名单里列出的一个朝鲜IT人员(Naoki Murano),项目管理人员在他们的聊天中分享了我的文章。

jvXUP0DEZLmknHOLMThafxwC5wwdV3pcKCLcGNiu.png结果是,就在两分钟之内,Naoki退出了聊天,并删除了他的Github

cK5dh6lYjLeodNZOP7QKAaJ3vAh4cgQDX3kI2srC.png

Related Reads

Bitcoin at 59,000 Is Not the Bottom, One Last Drop Needed! Chain Data and Liquidity Analysis: Where is BTC's True Bottom?

Based on analysis by trader Mr. Beggar, Bitcoin's (BTC) recent low of $59k is likely not the final cycle bottom. He argues that while a bottom is near, a final downward movement is still probable to target liquidity below that level, making a deeper low healthier for a sustainable reversal. Mr. Beggar's framework combines on-chain data for long-term cycles and liquidity-based technical analysis for shorter-term trades. His "four deep bear buying models" include Cointime Price (market cost weighted by coin holding time) and AVIV (an enhanced MVRV indicator), which currently suggest prices are nearing cyclical bottom zones. While a PSIP (Percent Supply in Profit) signal has flashed below 50%, it alone is not considered definitive; typically, the first signal is not the final bottom. He presents three potential scenarios for the current market: 1) a direct drop from here, 2) an upward liquidity sweep (stop hunt) of the recent high near $67.3k before declining, and 3) a direct reversal without new lows. He heavily discounts the third scenario due to significant un-swept liquidity in the $59k-$62.3k range, suggesting the market must revisit these levels. Mr. Beggar shares that he used on-chain signals to identify potential cycle tops in late 2024/early 2025 and later established low-leverage BTC-denominated short positions. He emphasizes the importance of risk management and staying within one's expertise ("strike zone"), warning against investing in assets like AI/semiconductor stocks simply because they are rising.

marsbit10m ago

Bitcoin at 59,000 Is Not the Bottom, One Last Drop Needed! Chain Data and Liquidity Analysis: Where is BTC's True Bottom?

marsbit10m ago

From Signal Monitoring to Strategy Copy Trading: How PPP Lowers the Barrier to Trading on Polymarket?

From Signal Monitoring to Strategy Copy Trading: How PPP Lowers the Barrier to Polymarket Trading The surge in trading demand on prediction markets like Polymarket, especially during events like the World Cup, exposes a common challenge for novice users: emotional and impulsive trading due to a lack of stable strategies and reliable signals. Prediction Position Platform (PPP) addresses this by serving as a Telegram-based tool for strategy discovery and automated copy-trading on Polymarket. PPP offers a suite of features through a subscription model. Key functionalities include 24/7 market signal monitoring (tracking smart money movements and rapid probability shifts), an "AI Address Analysis" tool to evaluate trader performance metrics, and specialized sections like a "World Cup Zone" for quick access to related markets. Its core value lies in two curated lists: the "Strategy Square," which identifies addresses suitable for long-term tracking based on comprehensive metrics like returns, win rate, and drawdowns, and the "Trading Leaderboard," highlighting recently outperforming addresses for short-term opportunities. Users can manually analyze any address or set up automated copy-trading with customizable parameters like investment amount and stop-loss. After initiating copy-trades, users can manage all positions from a unified dashboard, adjusting parameters or stopping follows as needed, and review historical performance data. Crucially, PPP employs a non-custodial wallet model, meaning user funds remain in their own self-custodied wallets, enhancing security and trust. In summary, PPP aims to reduce the learning curve and trial-and-error cost for Polymarket users by aggregating signals, curating and analyzing profitable traders, and facilitating automated, yet manageable, copy-trading execution.

Odaily星球日报10m ago

From Signal Monitoring to Strategy Copy Trading: How PPP Lowers the Barrier to Trading on Polymarket?

Odaily星球日报10m ago

From the White-Haired Stock God to the Billion-Dollar Fund Titan: The Smart People Shorting NVIDIA Are Getting Rich Using the Same Framework

From "white-haired stock god" to billionaire fund manager, those profiting from shorting NVIDIA share a common framework. The article analyzes the critical bottlenecks in the AI hardware supply chain, which have become key investment focal points. The core argument is that the real constraint on the AI boom isn't software or algorithms, but fundamental physical infrastructure. The piece dissects nine major bottlenecks, organized around the lifecycle of an AI accelerator circuit board. *Before the Board*: The pre-manufacturing stage faces constraints in EDA tools, new materials (like GaN, SiC, InP) replacing silicon, and the critical, non-renewable supply of helium for semiconductor fabrication. *On the Board*: The primary bottlenecks are High-Bandwidth Memory (HBM), essential for unleashing GPU power, and advanced packaging (e.g., CoWoS), required to integrate components. Both are in severe shortage. *Between Boards*: Chip-to-chip communication is hitting limits with copper, pushing photonics and optical interconnects (CPO) as the next-gen solution, with NVIDIA heavily investing in this area. *Around the Board*: Power delivery requires new materials (GaN/SiC) for efficient voltage conversion from 48V to sub-1V. High-density AI racks (120kW+) are forcing a shift from air to liquid cooling as the standard. *Beyond the Board*: The ultimate bottleneck is electricity. AI data centers consume power equivalent to mid-sized cities, and grid expansion lags far behind demand, causing project delays and a scramble for power contracts. Prominent investors like Leopold and "white-haired stock god" are heavily betting on these infrastructure bottlenecks. Leopold's fund, for instance, holds no NVIDIA stock but uses massive put options to short the semiconductor sector while going long on power and physical infrastructure. His thesis is that while chip competition may eventually erode margins, the scarcity of foundational elements like electricity is more persistent. The framework's validity is tied to the supply-demand gap. Major new capacity in HBM and photonics is scheduled for 2027-2028, but demand continues to outpace it. Experts like Intel's CEO suggest no relief before 2028. However, the article warns of a potential reversal around 2028-2029 if AI capex slows and new capacity floods the market, turning scarcity into oversupply. Until then, the imbalance persists.

链捕手41m ago

From the White-Haired Stock God to the Billion-Dollar Fund Titan: The Smart People Shorting NVIDIA Are Getting Rich Using the Same Framework

链捕手41m ago

Trading

Spot
Futures
活动图片