🧵 New investigation: Beejern, an active Oklahoma LLC, appears linked to a suspected DPRK IT worker cluster first identified through GitHub activity
The case connects GitHub aliases, company records, Upwork activity, manipulated imagery, shared infrastructure, and external DPRK research corroboration
🚨 WARNING (AGAIN)
DPRK threat actors are still rekting way too many of you via their fake Zoom / fake Teams meets.
They're taking over your Telegrams -> using them to rekt all your friends.
They've stolen over $300m via this method already.
Read this. Stop the cycle. 🙏
DPRK PSA: DO NOT interact with any of accounts claiming to be representative of @LightNodeVent. Communication and handles (@PulchraMens@TThompson @SirLeoThe1st) of company members are most likely COMPROMISED by DPRK Contagious Interview campaign through a ClickFix attack.
🚨 Hackers are using Microsoft Teams to pwn people and steal their crypto.
The attack is deceptively simple and relies on social engineering as well as malware.
They've already stolen millions of dollars from both project founders and normal users.
How it works🧵
If you want to be successful, you only need to do one thing: be proud of your work…
Genuinely. Alone. At night. On your own. When no one is watching. Know. In your bones. That you gave it your all.
When you do that, nothing can stop you.
@tanuki42_ If they care so much for the court order, can’t they implement a specific courtesy freeze time period for LE until that order is issued? I see 0 downside business wise.
@TobyFrei4@zachxbt@Andrey_10gwei 0x18...dC1C is an Asgard Vault =Thorchain infrastructure. You can double-check these types of addresses on Thorchain explorer itself.
🚨 Heads up all—some dudes have a slick, new way of dropping some nasty malware.
Feels infostealer-y on the surface but...its not.🫠
It'll really, deeply rekt you.
Pls share this w/ your friends, devs, and multisig signers. Everyone needs to be careful + stay skeptical. 🙏
Search -> expand and summarize -> ask deeper questions
Go from question to insight in less than 20 seconds, without ever leaving the chat.
Just shipped the update, more improvements on the way 🤫
Be extremely diligent in the emails you open and make sure you have proper key management in place for funds (multi-sig, custodian, ledger, etc.)
Another company in the space was hacked for several million dollars one week ago. Very likely to be Lazarus, the NK hacking group, using the same attack that effected MGNR, Arthur_0x, and Nexus Mutual.