Hackers utilize social engineering, move funds through Cambodian platform
A couple of recent reports have revealed how North Korean hackers have been moving funds to a Cambodian crypto payments platform while further insight has come to light with regard to how these hackers are compromising crypto companies.
Huoine Pay
On July 15, Reuters reported that Cambodian currency exchange and payments firm Huione Pay had received in excess of $150,000 in digital currency from a wallet associated with notorious North Korean hacking group Lazarus. Analysis of blockchain data demonstrated that the funds had been received by the Phnom Penh-headquartered payments firm in June 2023 and February 2024.

‘Pig butchering’
It’s understood that Lazarus stole those digital assets from three crypto firms during the months of June and July of 2023. While Huione has suggested that it was oblivious to the origin of the funds, a blog article by blockchain analytics company Elliptic, published to its website on July 10, suggested that “Huione Guarantee is an online marketplace that has become widely used by scam operators in South East Asia.”
Elliptic went on to assert that some of these scammers employ “pig butchering” techniques, where fraudsters manipulate the victim into investing into fraudulent crypto schemes. It added that “merchants on the platform offer technology, data and money laundering services, and have engaged in transactions totaling at least $11 billion.”
The National Bank of Cambodia explained to Reuters that the company is not permitted to trade crypto and that it "would not hesitate to impose any corrective measures" against Huione. The platform is believed to have strong ties to Cambodia’s ruling family. One of the firm’s three directors is understood to be a cousin of the Cambodian Prime Minister, Hun Manet.
The Lazarus hacking group is believed to have masterminded a $305 million hack of Japanese cryptocurrency DMM Bitcoin in May of this year. Pseudonymous on-chain investigator ZachXBT claimed on X that $35 million of the proceeds had been laundered through the Huione platform.
Compromising crypto businesses
In a related development, a report by DL News published on July 15 has found that North Korean hackers are employing a new tactic in order to compromise crypto businesses. The hackers are scanning the internet for job postings advertised by the companies they’re targeting and submitting bogus applications.
A report by the United Nations Security Council has revealed that in excess of 4,000 North Koreans have taken up employment with international technology firms. Part of the social engineering-based tactics employed by the hackers includes contriving to get employees within targeted companies to install malware.
Oftentimes, the resumes and LinkedIn profiles of real people are used in order to find a way in via the recruitment process. A report by DeFiLlama suggests that $664 million has been lost via instances of crypto hacking within the first half of 2024.


