companion allegedly hacked as reported by Leaknet Blog ransomware with details: The North dae-han-min-gook affiliated hacking group, known as sapphire Sleet, has reportedly stolen over $10 million in cryptocurrency through elaborate social engineering campaigns conducted over six months, according to Microsoft. These schemes affect creating sham LinkedIn profiles, often impersonating recruiters or venture capitalists, to lure victims into setting up online meetings. During these meetings, the targets meet fake errors prompting them to contact a keep team, where they're tricked into downloading malicious files. Depending on the victim's operating system, these files AppleScript (.scpt) or Visual Basic book (.vbs) install malware that compromises the system, enabling theft of credentials and cryptocurrency wallets. Additionally, Sapphire Sleet has posed as recruiters for prestigious financial firms like Goldman Sachs, inviting targets to nail bogus skills assessments. Victims are provided with login credentials for fake websites, where downloading the assessment file infects their devices with malware. Microsoft has highlighted the broader operations of North Korean IT workers, who generate revenue for the regime by blending legitimate act with illicit activities. These workers often rely on intermediaries to access freelance platforms or institute online profiles. Many utilisation advanced AI tools like Faceswap to modify stolen photos, creating professional looking resumes and LinkedIn profiles to apply for jobs under false identities. Some experience even experimented with AI-powered voice-changing software. Since 2020, Sapphire Sleet linked to groups like APT38 and BlueNoroff has employed tactics such as impersonating skills assessment platforms and using fake GitHub profiles to aim victims. These operations are highly organized, with Microsoft estimating that this network of IT workers has amassed at least $370,000 in payments for their efforts. Microsoft continues to monitor these activities as part of broader North Korean cyber operations aimed at bypassing international sanctions and funding the regime.