stole – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 02 Jul 2025 06:27:09 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 stole – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Remote Work Scam: North Koreans Stole $1 Million in Crypto, DOJ Says https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/ https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/#respond Wed, 02 Jul 2025 06:27:08 +0000 https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/

US prosecutors have charged four North Korean citizens with wire fraud and money laundering after they allegedly pretended to be remote IT workers to steal nearly $1 million in crypto.

The charges were filed in the state of Georgia and involve two blockchain companies based in the US and Serbia.

The US Department of Justice (DOJ) identified the suspects as Kim Kwang Jin, Kang Tae Bok, Jong Pong Ju, and Chang Nam Il. The group reportedly used fake and stolen IDs to hide that they were North Korean citizens.

What is Terra Luna? History & Crash Explained (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

They started operating from the United Arab Emirates in 2019 before later getting jobs at a blockchain startup in Atlanta and a crypto firm in Serbia between December 2020 and May 2021.

Kim and Jong are accused of using fake documents, including false identification, to secure employment. US Attorney Theodore S. Hertzberg said this method poses a risk for companies that rely on remote workers, as it can be difficult to confirm someone’s true identity.

After getting access to internal systems, the suspects carried out two separate thefts. In February 2022, Jong allegedly stole around $175,000 in cryptocurrency. A month later, Kim exploited smart contract code to take another $740,000.

The stolen money was then moved through mixing services and sent to exchange accounts controlled by Kang and Chang. These accounts were set up using fake Malaysian IDs, investigators said.

According to John A. Eisenberg, the assistant attorney general for national security, the stolen funds were meant to help North Korea avoid sanctions and support its banned weapons programs.

Recently, Dwayne Golden, a 57-year-old man from the US, was sentenced to nearly eight years in prison. What happened? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/feed/ 0 45292
Malware on Google Play, Apple App Store stole your photos—and crypto https://earlybirdsinvest.com/malware-on-google-play-apple-app-store-stole-your-photos-and-crypto/ https://earlybirdsinvest.com/malware-on-google-play-apple-app-store-stole-your-photos-and-crypto/#respond Mon, 23 Jun 2025 19:06:00 +0000 https://earlybirdsinvest.com/malware-on-google-play-apple-app-store-stole-your-photos-and-crypto/

Hacker starting at a smartphone

A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices.

The malware is a possible evolution of SparkCat, which Kaspersky discovered in January. SparkCat used optical character recognition (OCR) to steal cryptocurrency wallet recovery phrases from images saved on infected devices.

When installing crypto wallets, the installation process tells users to write down the wallet’s recovery phrase and store it in a secure, offline location.

Access to this seed phrase can be used to restore a crypto wallet and its stored assets on another device, making them a valuable target for threat actors.

While taking a screenshot of your seed phrase is never a good idea, some people do so for convenience.

A report by Kaspersky says that the new SparkKitty malware indiscriminately steals all images from an infected device’s photo gallery.

While Kaspersky believes that the malware is targeting crypto wallet seed phrases, the stolen data could also be used for other malicious purposes, like extortion, if the images contain sensitive content.

The SparkKitty malware

The SparkKitty campaign has been active since at least February 2024, spreading through both official Google and Apple app stores and unofficial platforms.

SparkKitty on Apple App Store
SparkKitty on Apple App Store
Source: Kaspersky

The malicious apps Kaspersky identified are 币coin on the Apple App Store and SOEX on Google Play, both having been removed by the time of this writing.

SOEX is a messaging app with cryptocurrency exchange features, downloaded over 10,000 times via Android’s official app store.

The malware app on Google Play
The malware app on Google Play
Source: Kaspersky

Kaspersky also discovered modded TikTok clones embedding fake online cryptocurrency stores, gambling apps, adult-themed games, and casino apps containing SparkKitty, distributed via unofficial channels.

TikTok clone app installed via unofficial sites
TikTok clone app installed via an iOS profile
Source: Kaspersky

On iOS, SparkKitty is embedded as fake frameworks (AFNetworking.framework, libswiftDarwin.dylib) and sometimes delivered via enterprise provisioning profiles.

On Android, the malware is embedded in Java/Kotlin apps, some of which use malicious Xposed/LSPosed modules.

The malicious framework uses the Objective-C ‘+load’ method to automatically execute its code when the app starts on iOS. A configuration check is performed by reading keys from the app’s Info.plist; execution proceeds only if values match expected strings.

On Android, the malware is triggered on app launch or at specific user-driven actions like opening a specified screen type. Upon activation, it retrieves and decrypts a remote configuration file using AES-256 (ECB mode) to get C2 URLs.

On iOS, the malware requests access to the photo gallery, while on Android, the malicious app requests the user to grant storage permissions to access images.

If permission is granted on iOS, the malware monitors the gallery for changes and exfiltrates any new or previously unuploaded images.

Image exfiltration code on iOS
Image exfiltration code on the iOS variant
Source: Kaspersky

On Android, the malware uploads images from the gallery, along with device identifiers and metadata. Kaspersky found some SparkKitty versions that use Google ML Kit OCR to detect and only upload images containing text.

Image exfiltration logic on Android
Image exfiltration logic on Android
Source: Kaspersky

SparkKitty is another example of malware slipping into official app stores, highlighting once more that users shouldn’t blindly trust software on vetted distribution channels.

All apps should be scrutinized for signs of fraud, such as fake reviews, publishers with doubtful backgrounds or histories, low downloads combined with a high number of positive reviews, etc.

During installation, requests for storage of gallery access should be treated with suspicion and denied if they’re not related to the app’s core functionality.

On iOS, avoid installing configuration profiles or certificates unless they come from a trusted source. On Android, enable Google Play Protect in settings and perform regular full-device scans.

Ultimately, cryptocurrency holders should not keep images of their wallet seed phrases on their mobile devices, as these are now actively targeted by malware. Instead, store them offline in a secure location.

BleepingComputer has contacted both Apple and Google to ask for a comment on how these apps slipped through the cracks and into their app stores.

“The reported app has been removed from Google Play and the developer has been banned,” Google told BleepingComputer.

“Android users are automatically protected against this app regardless of download source by Google Play Protect, which is on by default on Android devices with Google Play Services.”

BleepingComputer also contacted Apple about the apps and will update the story if we receive a response.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/malware-on-google-play-apple-app-store-stole-your-photos-and-crypto/feed/ 0 43711
Authorities Allege Scammers Stole $265,000,000 in Crypto To Buy Exotic Cars, Private Security and Other Luxuries https://earlybirdsinvest.com/authorities-allege-scammers-stole-265000000-in-crypto-to-buy-exotic-cars-private-security-and-other-luxuries/ https://earlybirdsinvest.com/authorities-allege-scammers-stole-265000000-in-crypto-to-buy-exotic-cars-private-security-and-other-luxuries/#respond Tue, 20 May 2025 03:38:34 +0000 https://earlybirdsinvest.com/authorities-allege-scammers-stole-265000000-in-crypto-to-buy-exotic-cars-private-security-and-other-luxuries/

A New Zealand man has been arrested for allegedly being a part of an international criminal organization that stole $265 million in crypto assets from seven people.

In a new press release, authorities allege that the unnamed Wellington man participated in a scheme that fraudulently obtained the crypto assets by manipulating victims between March and August 2024.

The U.S Department of Justice (DOJ) has charged the individual with racketeering, conspiracy to commit wire fraud and conspiracy to commit money laundering.

Twelve other people are facing charges in connection with the case, including individuals from Auckland and California.

According to prosecutors, the defendants laundered the proceeds of the scheme through various cryptocurrency exchanges before spending the funds to purchase luxury items such as handbags, clothes, cars, watches, private security, rental homes and expensive nightclub entertainment.

The other members of the group were recently arrested and charged by the DOJ as well. According to previous reports, the organization had a team behind them made up of hackers, callers, organizers, money launderers and residential burglars. The team has been operating as early as October 2023.

Last year, two members of the group, Malone Lam and Jeandiel Serrano, were arrested and charged in connection with a plot that allegedly saw them steal $230 million in crypto from a victim and then attempt to launder the funds using advanced methods.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/authorities-allege-scammers-stole-265000000-in-crypto-to-buy-exotic-cars-private-security-and-other-luxuries/feed/ 0 37216
NFT founder stole millions from Bitcoin project, investors allege https://earlybirdsinvest.com/nft-founder-stole-millions-from-bitcoin-project-investors-allege/ https://earlybirdsinvest.com/nft-founder-stole-millions-from-bitcoin-project-investors-allege/#respond Thu, 15 May 2025 06:44:31 +0000 https://earlybirdsinvest.com/nft-founder-stole-millions-from-bitcoin-project-investors-allege/

Several investors in a non-fungible token (NFT) project, Hashling NFT, have accused its founder of misappropriating millions of dollars in profits from the project and a closely tied Bitcoin mining operation.

According to the May 14 court filing in Illinois, the plaintiffs allege that their former business partner, Jonathan Mills, lied about transferring assets from Hashling NFT and at least $3 million from the Bitcoin mining project to a holding company — Satoshi Labs LLC (formerly known as Proof of Work Labs LLC), which Mills is the founder and CEO of.

The plaintiffs have sued Mills for fraud and breach of fiduciary duty, claiming that they have not received any of the equity returns that he supposedly promised. 

They also claim to have raised a combined $1.46 million from two NFT drops on the Solana and Bitcoin blockchains, but didn’t receive any returns from their investment. 

Excerpt of the plaintiffs’ claims made against Joshua Mills in an Illinois district court. Source: PACER

Mills allegedly began ghosting them shortly afterward, according to the plaintiffs, adding that he created a flawed shareholder agreement to falsely support his claim that the holding company controlled the project’s assets.

This was “rife with errors” to support his lie, the plaintiffs said.

According to the supposedly flawed shareholder agreement, Mills was to receive a 67% equity share in Proof of Work Labs (before he later renamed it to Satoshi Labs) while several other investors contributed up to $20,000 into the company in exchange for just 2% equity.

He allegedly assured them that their equity stakes would remain unchanged despite the name change.

Mills also held a 67% voting stake on all matters related to Proof of Work Labs (at the time) while no other partner held more than 2%.

Cointelegraph reached out to Mills but didn’t receive an immediate response.

Mills supposedly didn’t know much about NFTs

The Hashling NFT project was born from a different idea that Mills had initially discussed with one of the plaintiffs, Dustin Steerman, who initially established rapport with Mills from earlier collaborations.

They followed through with the Hashling NFT project despite Mills initially telling Steerman that he had no money and no NFT-related experience to contribute to the project.

Related: Bitcoin NFTs surpass Ronin in all-time sales

“[Mills] had a willingness to help push the project forward, and he did have an idea at the start,” the investor’s attorney, Clinton Ind of Ind Legal Group LLC told Law360.

“Even though that wasn’t the final idea, it did embolden it, and … everyone kind of enjoyed working together in those early stages.”

To ensure the Hashling NFT project’s success, Mills and Steerman recruited other investors, now also plaintiffs, to assist with everything from the NFT art and social media marketing to even attending NFT conferences in New York.

Mills even got his girlfriend to invest in the Hashling NFTs project, the plaintiffs claimed.

In addition to the fraud and breach of fiduciary actions, the plaintiffs also requested a constructive trust over the project’s assets and full legal restitution.

Magazine: Danger signs for Bitcoin as retail abandons it to institutions: Sky Wee

]]> https://earlybirdsinvest.com/nft-founder-stole-millions-from-bitcoin-project-investors-allege/feed/ 0 36319 Thailand seizes 63 illegal crypto mining rigs that stole over $327k in electricity https://earlybirdsinvest.com/thailand-seizes-63-illegal-crypto-mining-rigs-that-stole-over-327k-in-electricity/ https://earlybirdsinvest.com/thailand-seizes-63-illegal-crypto-mining-rigs-that-stole-over-327k-in-electricity/#respond Sun, 16 Mar 2025 17:57:28 +0000 https://earlybirdsinvest.com/thailand-seizes-63-illegal-crypto-mining-rigs-that-stole-over-327k-in-electricity/

Officials of Thailand’s Central Investigation Bureau (CIB) seized 63 illegal crypto mining machines on Friday, according to a report by The Nation. The illegal crypto mining rigs, worth around 2 million baht ($60,000), were found in three abandoned houses in the Pathum Thani province.

Officials conducted a raid after locals of the region complained about unidentified individuals stealing electricity from the region’s utility poles and transformers. The locals suspected that the stolen electricity was being used for cryptocurrency mining operations hidden in abandoned buildings.

Crypto mining requires massive amounts of electricity. Authorities estimate that the illicit mining rigs caused losses worth over 11 million baht (over $327 million) to the Metropolitan Electricity Authority.

The illegal mining rigs were controlled remotely

Police officials said that along with the mining rigs, they also confiscated three crypto mining controllers, three routers, three internet signal boosters, three modified electricity metres, a desktop computer, a laptop computer, and two bank passbooks. No arrests were made as the mining operations were being controlled remotely.

Officials found evidence, however, that the illicit operation had ties to a luxury house in Ram-Indra Soi 65 in Bangkok’s Khan Na Yao district. The CIB officials have requested a search warrant to raid the linked residence and locate the ring leader and other accomplices.

Authorities noted that besides causing damages to the electricity department, the illegal mining rigs also posed a major fire hazard. This is because the operations utilized high amounts of power but had no human monitoring.

Thailand has been plagued with illegal mining operations

Bitcoin miners are treated as manufacturers in Thailand and are subject to associated taxes. However, illegal crypto mining has been a rampant problem across Thailand and Southeast Asia for years.

In a raid conducted in January, authorities seized 996 illegal Bitcoin (BTC) mining rigs from the Phanat Nikhom district in Thailand.

In November 2024, authorities shut down nine illegal Bitcoin mining farms in the Surat Thani province. The farms were estimated to have stolen electricity worth nearly $300,000.

Similarly, in August, authorities raided a town west of Bangkok and found evidence of illegal crypto mining after locals complained about power outages.

XRP Turbo
]]>
https://earlybirdsinvest.com/thailand-seizes-63-illegal-crypto-mining-rigs-that-stole-over-327k-in-electricity/feed/ 0 25503