BPOI Banner
Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

North Korean Hackers Target Crypto Firms in ‘Hidden Risk’ Campaign

North Korean state-sponsored hackers expanded their arsenal, launching a new campaign dubbed ‘Hidden Risk’ that seeks to infiltrate crypto firms through malware disguised as legitimate documents.

In a Thursday report, hack research firm SentinelLabs connected the latest campaign to the notorious BlueNoroff threat actor, a subgroup of the infamous Lazarus Group, known for siphoning off millions to fund North Korea’s nuclear and weapons programs.

The series of attacks is a calculated effort to extract funds from the fast-growing $2.6 trillion crypto industry, taking advantage of its decentralized and often under-regulated environment. 

The FBI recently issued warnings about North Korean cyber actors increasingly targeting employees of DeFi and ETF firms through tailored social engineering campaigns. 

The hackers’ latest campaign appears to be an extension of those efforts, focusing on breaching crypto exchanges and financial platforms.

Instead of their usual strategy of grooming social media victims, the hackers rely on phishing emails that appear as crypto news alerts, which began cropping up in July, according to the report.

Social media grooming typically refers to an elaborate strategy where cybercriminals build trust with targets over time by engaging with them on platforms like LinkedIn or Twitter. 

The emails, disguised as updates on Bitcoin (BTC) prices or the latest trends in decentralized finance (DeFi), lure victims into clicking on links that appear to lead to legitimate PDF documents, per the report.

But rather than opening a harmless file, unsuspecting users inadvertently download a malicious application onto their Macs.

The report found the new malware more concerning because it cleverly bypasses Apple’s built-in security protections. The hackers get their software signed with legitimate Apple Developer IDs, allowing it to evade macOS’s Gatekeeper system. 

Once installed, the malware uses hidden system files to stay undetected, even after the computer is restarted, and it communicates with remote servers controlled by the hackers.

The SentinelLabs report advises macOS users, particularly within organizations, to tighten their security measures and heighten their awareness of possible risks.

Edited by Sebastian Sinclair

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

Sebastian Sinclair

https://decrypt.co/290782/north-korean-hackers-target-crypto-firms-in-hidden-risk-campaign

2024-11-08 05:15:16

bitcoin
Bitcoin (BTC) $ 88,761.78 3.53%
ethereum
Ethereum (ETH) $ 3,091.57 6.67%
tether
Tether (USDT) $ 0.998193 0.49%
solana
Solana (SOL) $ 211.06 2.34%
bnb
BNB (BNB) $ 623.12 1.71%
dogecoin
Dogecoin (DOGE) $ 0.386757 8.23%
xrp
XRP (XRP) $ 0.710603 0.54%
usd-coin
USDC (USDC) $ 0.999245 0.25%
staked-ether
Lido Staked Ether (STETH) $ 3,087.12 6.81%
cardano
Cardano (ADA) $ 0.546347 8.18%
tron
TRON (TRX) $ 0.178589 1.13%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 8.05%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,723.09 4.97%
the-open-network
Toncoin (TON) $ 5.21 4.19%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 88,463.70 2.92%
avalanche-2
Avalanche (AVAX) $ 31.69 8.47%
sui
Sui (SUI) $ 3.26 0.06%
weth
WETH (WETH) $ 3,088.39 6.53%
pepe
Pepe (PEPE) $ 0.00002 9.23%
bitcoin-cash
Bitcoin Cash (BCH) $ 420.58 4.17%
chainlink
Chainlink (LINK) $ 12.97 9.08%
polkadot
Polkadot (DOT) $ 4.80 10.65%
leo-token
LEO Token (LEO) $ 7.41 1.47%
near
NEAR Protocol (NEAR) $ 5.19 4.82%
aptos
Aptos (APT) $ 11.21 8.19%
litecoin
Litecoin (LTC) $ 78.11 1.61%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,249.80 6.73%
usds
USDS (USDS) $ 1.01 0.86%
uniswap
Uniswap (UNI) $ 8.19 9.89%
crypto-com-chain
Cronos (CRO) $ 0.155944 12.88%
internet-computer
Internet Computer (ICP) $ 8.08 7.76%
dogwifcoin
dogwifhat (WIF) $ 3.81 1.57%
stellar
Stellar (XLM) $ 0.12291 6.15%
bittensor
Bittensor (TAO) $ 497.37 11.61%
dai
Dai (DAI) $ 0.99924 0.42%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.24 8.53%
ethereum-classic
Ethereum Classic (ETC) $ 21.59 5.40%
whitebit
WhiteBIT Coin (WBT) $ 22.05 1.56%
kaspa
Kaspa (KAS) $ 0.122961 8.74%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.02%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.357313 10.30%
blockstack
Stacks (STX) $ 1.84 8.47%
monero
Monero (XMR) $ 144.50 3.33%
render-token
Render (RENDER) $ 6.69 9.15%
okb
OKB (OKB) $ 43.30 1.88%
bonk
Bonk (BONK) $ 0.000037 5.26%
aave
Aave (AAVE) $ 163.85 11.45%
mantle
Mantle (MNT) $ 0.70963 4.16%
injective-protocol
Injective (INJ) $ 23.97 8.27%
first-digital-usd
First Digital USD (FDUSD) $ 0.996314 1.11%