North Korean Hackers Impersonate Crypto VCs in New Phishing Scam

[ad_1]

Image source: Pixabay

BlueNoroff, a subgroup of the North Korean state-sponsored hacking group Lazarus, is now posing as venture capitalists looking to invest in crypto startups in a new phishing method.

According to a new report from cybersecurity firm Kaspersky, BlueNoroff has created more than 70 fake domains that seek to impersonate venture capitalists and banks. The vast majority of fake VCs presented themselves as well-known Japanese companies, while others took on the identities of American and Vietnamese companies.

These fake VCs then target cryptocurrency startups that treat smart contracts, DeFi, Blockchain, and the FinTech industry with new malware delivery methods.

Kaspersky says BlueNoroff also uses software to circumvent Mark-of-the-Web (MOTW) technology, which ensures that a message from Windows appears to warn users when they attempt to open a file downloaded from the Internet. In a press release, the company detailed:

“Attackers used phishing techniques to attempt to infect targeted businesses, then intercept large cryptocurrency transfers, change the recipient’s address, and push the transfer amount to the limit, essentially draining the account by a single trade.”

The name BlueNoroff was coined by Kaspersky in 2016 when its researchers were investigating the notorious attack on the Central Bank of Bangladesh.

Kaspersky noted that a citizen of the United Arab Emirates, who was in the sales department responsible for signing the contracts, fell victim to the BlueNoroff group after downloading a Word document called “Shamjit Client Details Form.doc”, which allowed hackers to log into his computer and extract information as they attempted to execute even more powerful malware.

As reported, North Korean hackers have stolen about 1.5 trillion won ($1.2 billion) worth of crypto assets since 2017. More than half of that tally, or about 800 billion won ($626 million dollars), have been stolen so far this year.

According to South Korea’s main spy agency, the National Intelligence Service, North Korea is using the stolen crypto assets to fund its nuclear program and prop up its fragile economy which has been shrinking steadily over the past two years. amid harsh UN sanctions and COVID-19. pandemic.

Seongsu Park, a senior security researcher with Kaspersky’s Global Research and Analysis Team (GReAT), asserted that North Korean hackers will further increase their illicit cyber activities in 2023. He said:

“As predicted in the recent APT forecast for 2023, the coming year will be marked by cyber outbreaks with the greatest impact, the strength of which has never been seen before.”

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMicGh0dHBzOi8vY3J5cHRvbmV3cy5jb20vbmV3cy9rYXNwZXJza3ktcmVwb3J0LW5vcnRoLWtvcmVhbi1oYWNrZXJzLWltcGVyc29uYXRpbmctY3J5cHRvLXZjcy1uZXctcGhpc2hpbmctc2NhbS5odG3SAQA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts