Blockchain

Kaspersky Reports: Kimsuky Hackers Target Crypto Firms with Malware

North Korea’s Kimsuky Hacking Group Targets South Korean Crypto Firms

North Korea’s notorious Kimsuky hacking group, also known as APT43, has been reportedly launching cyberattacks on two South Korean crypto firms using a previously undocumented Golang-based malware named – Durian.

Durian Malware Overview

Per findings from cybersecurity solutions giant Kaspersky, Durian is characterized by its “comprehensive backdoor functionality.” This feature enables the execution of delivered commands, additional file downloads and exfiltration of files.

Details of the Attacks

The attacks reportedly took place between August and November 2023, involving a South Korean software exploit to gain initial access.

“Based on our telemetry, we pinpointed two victims within the South Korean cryptocurrency sector. The first compromise occurred in August 2023, followed by a second in November 2023.”

Tools Deployed by Kimsuky

Once the malware is established and operational on the victim’s systems, Durian deployed additional tools, including Kimsuky’s backdoor AppleSeed, and a custom proxy tool named LazyLoad.

Interestingly, LazyLoad tool links to Andariel, a sub-group within the notorious Lazarus. This also raises the suspicion of shared tactics among both North Korean threat groups, the Hacker News reported.

Kimsuky’s History

Per reports, Kimsuky started at least 2012 and is under the North Korea’s Reconnaissance General Bureau (RGB), the country’s military intelligence agency.

Kimsuky’s Phishing Tactics

Kimsuky group is well-known to have conducted various phishing attacks via email to steal cryptos.

In December 2023, the treat group disguised as South Korean government agency reps and journalists to steal cryptocurrencies. A total of 1,468 people fell victim to the crypto hackers between March and October 2023, according to police reports.

Some of the victims also included retired government officials from diplomacy, military and national security. The perpetrators reportedly sent legit-looking phishing mails to execute the dubious act.

Previous Targets of Kimsuky

The state-backed hacking group had previously targeted Russian aerospace defense companies “taking advantage of the coronavirus pandemic.”

According to Kommersant report, RT-Inform, the IT security arm of the Russian state-owned tech agency Rostec, noted that there has been an increase in the number of cyberattacks on the IT network during pandemic from April to September 2020. However, it neither denied nor confirmed the Kimsuky attack reports.

Leave a Reply

Your email address will not be published. Required fields are marked *

Información básica sobre protección de datos Ver más

  • Responsable: Masha Media News.
  • Finalidad:  Moderar los comentarios.
  • LegitimaciĂłn:  Por consentimiento del interesado.
  • Destinatarios y encargados de tratamiento:  No se ceden o comunican datos a terceros para prestar este servicio. El Titular ha contratado los servicios de alojamiento web a Banahosting que actĂşa como encargado de tratamiento.
  • Derechos: Acceder, rectificar y suprimir los datos.
  • InformaciĂłn Adicional: Puede consultar la informaciĂłn detallada en la PolĂ­tica de Privacidad.

You May Also Like

DeFi

📰 Table Of Contents1 Layer N Welcomes Luc Froehlich to Advisory Board1.1 Protocol’s Innovative Approach2 Layer N Unveils Nord Roll-up Testnet2.1 Nord Roll-up Features3...

Bitcoin

📰 Table Of Contents1 Argentinian Regulators and El Salvador Discuss Bitcoin Adoption1.1 Exploring Possible Cooperation Agreements1.2 Learning from El Salvador’s Bitcoin Experience1.3 Strengthening Ties...

Blockchain

đź“° Table Of Contents1 Ledger Stax Hardware Wallet Shipping Update2 Design Challenges and Delay2.1 Enhanced User Experience3 Ledger Stax Pricing and Security Features3.1 Production...

Bitcoin

📰 Table Of Contents1 Biden’s Decision on SEC’s Crypto Regulations Nears1.1 Overview of the Situation1.2 Potential Outcomes of Presidential Action1.3 Implications for Bitcoin and...

DeFi

📰 Table Of Contents1 Pseudonymous Developer Confesses to Stealing Funds from Cypher Protocol1.1 Hoak’s Confession and Fund Theft1.2 Transfer of Funds to Binance1.3 Impact...

Blockchain

đź“° Table Of Contents1 Binance France Ownership Restructuring1.1 Reasons for Ownership Change1.2 New Shareholders1.3 Yulong Yan1.4 Lihua He1.5 Global Restructuring Project1.6 Regulatory Challenges and...

Ethereum

📰 Table Of Contents1 Fake Crypto Airdrops Targeting Investors1.1 Crypto Scam Victim’s Experience1.2 Airdrop Scams and Their Tactics1.3 Preventative Measures for Investors1.4 Importance of...

Blockchain

đź“° Table Of Contents1 Interview with Jon Trask, CEO of Dimitra: Revolutionizing Agriculture with Blockchain and AI1.1 Revolutionizing Agriculture Across Africa and the Globe1.2...

Copyright © 2024 CRYPTOWIRE.TOP. All rights reserved. This website provides educational content, emphasizing that investing involves risks. Ensure you conduct thorough research before investing and be ready for any potential losses. For those over 18 and interested in gambling: Online gambling laws differ across countries; adhere to your local regulations. By using this site, you agree to our terms, including the presence of affiliate links that do not impact our evaluations. Cryptocurrency offers on this site are not in line with UK financial promotion regulations and are not aimed at UK consumers.

Exit mobile version