As security measures become more stringent, the tactics employed shift from reliance on technology to a focus on individuals. Malicious actors are infiltrating cryptocurrency companies by applying for jobs, successfully passing background checks, participating in Zoom interviews, and gradually establishing trust over several months. Eventually, they execute attacks that typical security measures are unprepared to detect, as the intruder is already within the organization.
Ripple is actively providing Crypto ISAC with critical profile information that helps illustrate these patterns across different companies. This includes LinkedIn profiles, email addresses, geographical locations, and contact details. Such data enables security teams to identify candidates they recently interviewed as the same individuals who previously failed background checks at multiple other companies.
“The most effective security strategy in the crypto world is a collaborative one,” Ripple stated on X. “A threat actor who fails at one company may apply to three others within the same week. Without shared intelligence, each organization starts from scratch.”
The extensive influence of the Lazarus Group within the cryptocurrency arena is now evident enough to begin influencing not only security measures but also legal actions.
This past Monday, a lawyer for victims of North Korean terrorism issued restraining notices to Arbitrum DAO, claiming that the 30,765 ETH held since the Kelp bridge breach in April is considered North Korean assets under U.S. enforcement regulations.
