• Economy
  • Investing
  • Editor’s Pick
  • Stock
Evil Shark Trades
Editor's Pick

North Korean Hackers Kimsuky Deployed Malware Targeting Crypto Firms: Kaspersky

by May 13, 2024
by May 13, 2024

North Korea’s notorious Kimsuky hacking group, also known as APT43, has been reportedly launching cyberattacks on two South Korean crypto firms using a previously undocumented Golang-based malware named – Durian.

Per findings from cybersecurity solutions giant Kaspersky, Durian is characterized by its “comprehensive backdoor functionality.” This feature enables the execution of delivered commands, additional file downloads and exfiltration of files.

The attacks reportedly took place between August and November 2023, involving a South Korean software exploit to gain initial access.

“Based on our telemetry, we pinpointed two victims within the South Korean cryptocurrency sector. The first compromise occurred in August 2023, followed by a second in November 2023.”

Once the malware is established and operational on the victim’s systems, Durian deployed additional tools, including Kimsuky’s backdoor AppleSeed, and a custom proxy tool named LazyLoad.

Interestingly, LazyLoad tool links to Andariel, a sub-group within the notorious Lazarus. This also raises the suspicion of shared tactics among both North Korean threat groups, the Hacker News reported.

Per reports, Kimsuky started at least 2012 and is under the North Korea’s Reconnaissance General Bureau (RGB), the country’s military intelligence agency.

Kimsuky’s Mail Mafia


Kimsuky group is well-known to have conducted various phishing attacks via email to steal cryptos.

In December 2023, the treat group disguised as South Korean government agency reps and journalists to steal cryptocurrencies. A total of 1,468 people fell victim to the crypto hackers between March and October 2023, according to police reports.

Some of the victims also included retired government officials from diplomacy, military and national security. The perpetrators reportedly sent legit-looking phishing mails to execute the dubious act.

The state-backed hacking group had previously targeted Russian aerospace defense companies “taking advantage of the coronavirus pandemic.”

According to Kommersant report, RT-Inform, the IT security arm of the Russian state-owned tech agency Rostec, noted that there has been an increase in the number of cyberattacks on the IT network during pandemic from April to September 2020. However, it neither denied nor confirmed the Kimsuky attack reports.

The post North Korean Hackers Kimsuky Deployed Malware Targeting Crypto Firms: Kaspersky appeared first on Cryptonews.

0 comment
0
FacebookTwitterPinterestEmail

previous post
Hong Kong’s New Spot Bitcoin ETFs Attract Investors from Mainland China
next post
Chinese Police Arrest Six Suspects in $300 Million Cryptocurrency Money Laundering Case

You may also like

Josh Fraser, Co-Founder of Origin Protocol, on Liquid...

Hong Kong Legislator Raises Concern Over Crypto Licensing...

Bitcoin Price Prediction: $150K Forecast and ETF Market...

Veteran Analyst Peter Brandt Predicts Bitcoin Price to...

Robinhood Implements Buying Restrictions on GameStop As Roaring...

Over $3 Billion Worth of ETH Withdrawn from...

Matter Labs Withdraws ‘ZK’ Trademark Application After Industry...

Rwanda to Roll Out CBDC By 2026 After...

El Salvador’s President Nayib Bukele Sworn in for...

FTX Estate Sells Off Remaining Anthropic Holdings Amid...

Enter Your Information Below To Receive Free Trading Ideas, Latest News And Articles.






    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Recent Posts

    • Pentagon unveils new medal for troops deployed in Trump’s southern border crackdown
    • Federal judge rules Trump appointee Alina Habba is unlawfully serving as US attorney
    • Walmart boosts sales outlook as it says tariff costs are rising
    • ‘Maine’s Mamdani’: Maine GOP chief issues warning about new challenger looking to oust Susan Collins
    • How a ship that glides like a pelican could change travel and defense

    Categories

    • Economy (7,093)
    • Editor's Pick (3,862)
    • Investing (2,826)
    • Stock (1,426)
    Email Whitelisting About Us Terms & Conditions Privacy Policy Contact Us

    Disclaimer: Evilsharktrades.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Copyright © 2024 EvilSharkTrades.com


    Back To Top
    Evil Shark Trades
    • Economy
    • Investing
    • Editor’s Pick
    • Stock