Binance Exposes Sophisticated North Korean Cyberattacks on Crypto

Binance CSO Jimmy Su reveals that state-level North Korean attackers, notably the Lazarus Group, exploit fake resumes, malicious NPM packages, and fake job offers, prompting collaborative security intelligence sharing among crypto platforms.

Summary

On August 13, Binance Chief Security Officer Jimmy Su disclosed that the platform receives numerous fake resumes daily linked to North Korean attackers, specifically the Lazarus Group. He detailed tactics including embedding malicious code in public NPM packages and issuing fake job offers. Binance collaborates with other major platforms via Telegram and Signal to share security intelligence and mitigate these threats.

Terms & Concepts
  • Lazarus Group: A North Korea-affiliated hacking group known for executing sophisticated cyberattacks, including those targeting the crypto industry.
  • NPM package: A repository module used in Node.js for distributing open-source code, which can be exploited if malicious code is embedded.