CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

North Korean Hackers On the Prowl

November 4, 2023
in Crypto News
Reading Time: 2 mins read
A A
0
CoinEx Invites Hackers to Negotiate, Promises Bug Bounty Reward
0
SHARES
2
VIEWS
ShareShareShareShareShare

RELATED POSTS

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

In a recent revelation, Elastic Security Labs has uncovered a sophisticated cyber intrusion by North Korean hackers believed to be associated with the Lazarus group.

This incident, tracked as REF7001, involved the use of a new macOS malware named Kandykorn, which has been specifically designed to target blockchain engineers involved in cryptocurrency exchange platforms.

North Korean Hackers Target Crypto Engineers with Discord-Distributed Malware

Elastic Security Labs has exposed a sophisticated cyber intrusion by North Korean hackers believed to be associated with the notorious Lazarus Group. This incident, which targeted blockchain engineers involved in cryptocurrency exchange platforms, utilized a deceptive Python program masquerading as a cryptocurrency arbitrage bot.

What sets this attack apart is its distribution method: the attackers distributed the malware through a private message on a public Discord server, which is atypical of macOS intrusion tactics.

“The victim believed they were installing an arbitrage bot, a software tool capable of profiting from cryptocurrency rate differences between platforms,” explained the researchers at Elastic Security Labs.

After installation, the Kandykorn malware initiates communication with a command-and-control (C2) server, utilizing encrypted RC4 and implementing a distinct handshake mechanism. Instead of actively polling for commands, it patiently awaits them. This sophisticated method enables hackers to retain control over the compromised systems discreetly.

Kandykorn Malware Tactics Reveal Ties to Lazarus Group

Elastic Security Labs has provided valuable insights into the capabilities of Kandykorn, showcasing its proficiency in performing file upload and download, process manipulation, and execution of arbitrary system commands. Of particular concern is its utilization of reflective binary loading, a fileless execution technique associated with the notorious Lazarus Group. The Lazarus Group is renowned for its involvement in cryptocurrency theft and evasion of international sanctions.

Furthermore, there is compelling evidence linking this attack to the Lazarus Group in North Korea. The similarity in techniques, network infrastructure, certificates used to sign malicious software, and custom methods for detecting Lazarus Group activities all point towards their involvement.

Additionally, on-chain transactions have revealed connections between security breaches at Atomic Wallet, Alphapo, CoinsPaid, Stake.com, and CoinEx. These connections further prove the Lazarus Group’s participation in these exploits.

In a separate recent incident, the Lazarus Group attempted to compromise Apple computers running macOS by deceiving users into downloading a crypto trading app from GitHub. Once the unsuspecting users installed the software and granted it administrative access, the attackers gained a backdoor entry into the operating system, allowing for remote access.

By delving into these details, Elastic Security Labs has shed light on the sophisticated tactics employed by the Lazarus Group, emphasizing the importance of robust cybersecurity measures to safeguard against such threats.

SPECIAL OFFER (Sponsored)

Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.

Credit: Source link

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Are Solana (SOL) and Avalanche (AVAX) About to Make a Shocking Market U-turn?

Next Post

Watch Out for These Massive Token Unlocks in November

Related Posts

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
Crypto News

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026
Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)
Crypto News

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

April 8, 2026
Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link
Crypto News

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

April 8, 2026
Next Post
Watch Out for These Massive Token Unlocks in November

Watch Out for These Massive Token Unlocks in November

Trader Says Ethereum Rival That’s Exploded Over 300% To ‘Keep Running,’ Unveils Targets for Chainlink and Sushi

Trader Says Ethereum Rival That’s Exploded Over 300% To ‘Keep Running,’ Unveils Targets for Chainlink and Sushi

Recommended Stories

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

April 8, 2026
Can US-Iran new peace deal signal keep Bitcoin above $70,000?

Can US-Iran new peace deal signal keep Bitcoin above $70,000?

April 8, 2026
Treasury Proposes Stablecoin AML Rules as Bessent Vows to Protect US Financial System – Crypto News Bitcoin News

Treasury Proposes Stablecoin AML Rules as Bessent Vows to Protect US Financial System – Crypto News Bitcoin News

April 8, 2026

Popular Stories

  • Aptos (APT) Technical Analysis: Wyoming Stablecoin Partnership Fuels Bullish Momentum at $4.60

    MATIC Price Prediction: $0.80 Target by November 2025 Despite Current Bearish Momentum

    0 shares
    Share 0 Tweet 0
  • Trader Says DeFi Altcoin Aave Witnessing Clear Trend Switch, Updates Forecast on Two Low-Cap Coins

    0 shares
    Share 0 Tweet 0
  • US Bans AI-Generated Voices Used in Scam Robocalls After Biden Impersonation Frauds

    0 shares
    Share 0 Tweet 0
  • Executives From Coinbase and Other Crypto Firms To Testify at Hearing on Digital Assets in Washington

    0 shares
    Share 0 Tweet 0
  • Leading US-based energy firm explores Bitcoin mining

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
  • SEC Opens Proceedings on NYSE Proposal to List Grayscale Crypto ETF Options – Regulation Bitcoin News
  • Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.