North Korean Lazarus Group Linked to New Cryptocurrency Hacking Scheme
The Lazarus group, a North Korean hacking organization previously linked to criminal activity, has been connected to a new attack scheme to breach systems and steal cryptocurrency from third parties. The campaign, which...
The Lazarus group, a North Korean hacking organization previously linked to criminal activity, has been connected to a new attack scheme to breach systems and steal cryptocurrency from third parties. The campaign, which uses a modified version of an already existing malware product called Applejeus, uses a crypto site and even documents to gain access to systems.
Modified Lazarus Malware Used Crypto Site as FacadeVolexity, a Washington D.C.-based cybersecurity firm, has linked Lazarus, a North Korean hacking group already sanctioned by the U.S. government, with a threat involving the use of a crypto site to infect systems in order to steal info and cryptocurrency from third parties.
A blog post issued on Dec. 1 revealed that in June, Lazarus registered a domain called “bloxholder.com,” which would be later established as a business offering services of automatic cryptocurrency trading. Using this site as a facade, Lazarus prompted users to download an application that served as a payload to deliver the Applejeus malware, directed to steal private keys and other data from the users’ systems.
The same strategy has been used by Lazarus before. However, this new scheme uses a technique that allows the application to “confuse and slow down” malware detection tasks.
Document MacrosVolexity also found that the technique to deliver this malware to final users changed in October. The method morphed to use Office documents, specifically a spreadsheet containing macros, a sort of program embedded in the documents designed to install the Applejeus malware in the computer.
The document, identified with the name “OKX Binance & Huobi VIP fee comparision.xls,” displays the benefits that each one of the VIP programs of these exchanges supposedly offers at their different levels. To mitigate this kind of attack, it is recommended to block the execution of macros in documents, and also scrutinize and monitor the creation of new tasks in the OS to be aware of new unidentified tasks running in the background. However, Veloxity did not inform on the level of reach that this campaign has attained.
Lazarus was formally indicted by the U.S. Department of Justice (DOJ) in Feb. 2021, involving an operative of the group linked to a North Korean intelligence organization, the Reconnaissance General Bureau (RGB). Before that, in March 2020, the DOJ indicted two Chinese nationals for aiding in the laundering of more than $100 million in cryptocurrency linked to Lazarus’ exploits.
What do you think about Lazarus’ latest cryptocurrency malware campaign? Tell us in the comments section below.
Original source
Read on Bitcoin NewsRelated market context
Crypto Laundering Network Linked To Ransomware Gangs Dismantled By Law Enforcement
TL;DR Chainalysis says law enforcement has dismantled AudiA6, a crypto laundering network linked to ransomware and darknet activit...
U.S. Charges Two Men for $389 Million Bitcoin and Crypto Money Laundering Scheme Tied to Dark Web
Bitcoin Magazine U.S. Charges Two Men for $389 Million Bitcoin and Crypto Money Laundering Scheme Tied to Dark Web Federal prosecu...
Coinbase Policy Push and ETF Speculation Drive Crypto Markets as North American Trading Volume Surges 1,000%
Coinbase unveils a policy proposal as ETF speculation lifts Bitcoin-linked altcoins and North American trading volume surges 1,000...
North Korea declares denuclearization irreversibly terminated, raising stakes for crypto security
North Korea's stance heightens geopolitical tensions and underscores the urgent need for enhanced cybersecurity measures in the cr...
SpaceX-linked products see $9B in trading, $5.6B on Binance in 24 hours
The surge in SpaceX-linked crypto trading highlights the growing role of digital assets as a parallel financial market, influencin...
Kraken becomes first crypto exchange to sponsor the FIFA World Cup as Brazil and Morocco kick off Group C
Kraken's World Cup sponsorship highlights crypto's growing integration into mainstream sports, potentially boosting global adoptio...