最新报道:According to Bijie.com, ZachXBT revealed that a source hacked into the devices of North Korean IT personnel and discovered that a small group of them used over 30 fake identities to obtain developer positions, purchased Upwork and LinkedIn accounts using government IDs, and worked through AnyDesk. The relevant data included Google Drive exports, Chrome profiles, and screenshots. The wallet address 0x78e1 was closely associated with the $680,000 attack on the Favrr platform in June 2025. Additional North Korean IT personnel have been identified. The group used Google products to schedule tasks, purchase social networks (SSNs), AI subscriptions, and VPNs. Browsing history revealed that they frequently used Google Translate for Korean translation and had Russian IP addresses. Recruiter oversight and a lack of coordination between services are major challenges in combating this activity.