Cointime

Download App
iOS & Android

North Korean Lazarus Group Linked to New Cryptocurrency Hacking Scheme

The Lazarus group, a North Korean hacking organization previously linked to criminal activity, has been connected to a new attack scheme to breach systems and steal cryptocurrency from third parties. The campaign, which uses a modified version of an already existing malware product called Applejeus, uses a crypto site and even documents to gain access to systems.

Modified Lazarus Malware Used Crypto Site as Facade

Volexity, a Washington D.C.-based cybersecurity firm, has linked Lazarus, a North Korean hacking group already sanctioned by the U.S. government, with a threat involving the use of a crypto site to infect systems in order to steal info and cryptocurrency from third parties.

A blog post issued on Dec. 1 revealed that in June, Lazarus registered a domain called “bloxholder.com,” which would be later established as a business offering services of automatic cryptocurrency trading. Using this site as a facade, Lazarus prompted users to download an application that served as a payload to deliver the Applejeus malware, directed to steal private keys and other data from the users’ systems.

The same strategy has been used by Lazarus before. However, this new scheme uses a technique that allows the application to “confuse and slow down” malware detection tasks.

Document Macros

Volexity also found that the technique to deliver this malware to final users changed in October. The method morphed to use Office documents, specifically a spreadsheet containing macros, a sort of program embedded in the documents designed to install the Applejeus malware in the computer.

The document, identified with the name “OKX Binance & Huobi VIP fee comparision.xls,” displays the benefits that each one of the VIP programs of these exchanges supposedly offers at their different levels. To mitigate this kind of attack, it is recommended to block the execution of macros in documents, and also scrutinize and monitor the creation of new tasks in the OS to be aware of new unidentified tasks running in the background. However, Veloxity did not inform on the level of reach that this campaign has attained.

Lazarus was formally indicted by the U.S. Department of Justice (DOJ) in Feb. 2021, involving an operative of the group linked to a North Korean intelligence organization, the Reconnaissance General Bureau (RGB). Before that, in March 2020, the DOJ indicted two Chinese nationals for aiding in the laundering of more than $100 million in cryptocurrency linked to Lazarus’ exploits.

Comments

All Comments

Recommended for you

  • BTC breaks through $69,500

    the market shows BTC has broken through $69,500 and is now trading at $69,502.89, with a 24-hour decline of 1.03%. The market is volatile, so please be prepared for risk control.

  • BNB falls below $570

    the market shows that BNB has fallen below $570 and is now trading at $569.7, with a 24-hour decline of 1.18%. The market is volatile, so please be cautious in risk control.

  • BTC falls below $69,500

    market shows BTC has fallen below $69,500, currently trading at $69,484.01, with a 24-hour decline of 1.71%. The market is volatile, so please take precautions to manage risks.

  • BTC falls below $70,000

     market shows BTC has fallen below $70,000 and is currently trading at $69,969.51, with a 24-hour decline of 1.21%. The market is volatile, so please be prepared for risk control.

  • BTC breaks through $71,500

    the market shows BTC has broken through $71,500 and is now trading at $71,502, with a 24-hour increase of 0.24%. The market is volatile, so please be prepared for risk control.

  • ILV breaks through $35

    according to market trends, ILV has broken through $35 and is currently trading at $35.02, with a 24-hour increase of 0.6%. The market is volatile, so please be prepared for risk control.

  • BTC breaks through $70,500

     the market shows that BTC has broken through $70,500 and is now trading at $70,503.37, with a 24-hour decline of 1.91%. The market is volatile, so please manage your risks.

  • APT falls below $9

    according to market data, APT has fallen below $9 and is currently trading at $8.99, with a 24-hour decline of 4.26%. The market is volatile, so please be prepared for risk control.

  • APT breaks through $9

    market data shows that APT has broken through $9 and is now trading at $9.01, with a 24-hour decline of 5.26%. The market fluctuations are significant, so please be prepared for risk control.

  • ZachXBT: Crypto exchange M2 was hacked yesterday and about $13 million was stolen

    On November 1st, according to online detective ZachXBT on his personal channel, the cryptocurrency trading platform M2 was hacked yesterday, and approximately $13 million was stolen from multiple hot wallets.