Lazarus Hacker Group Continues to Target Crypto Using Faked Trading Software

Lazarus Hacker Group Continues to Target Crypto Using Faked Trading Software
ôîòî ïîêàçàíî ñ : bitcoinmagazine.com

2019-4-2 21:54


This article was originally published by 8btc and written by Lylian Tang.

The Chinese security service provider 360 Security has issued a warning that a large number of crypto exchanges have been targeted by the North Korean hacker group Lazarus and that the number is still rising after the recent hacks of crypto exchanges DragonEx, Etbox and BiKi.

360 Core Security found that Lazarus, also known as the ATP-C-26 group, used software called “Worldbit-bot” to carry out its active attacks. The crypto exchange DragonEx fell victim to it on March 24, 2019, leading to a loss of $7.09 million, according to the 360 Security report.

The analysis by the 360 Advanced Threat Response Team detailed that the attacking group registered two domains, wb-invest.net and wb-bot.org, last October in preparation for the attacks. Then they faked the cryptocurrency trading software Worldbit-bot based on the open-sourced “Qt Bitcoin Trader,” which was embedded with malicious code. The malicious software was then camouflaged within a regular automated crypto trading platform under the domains of wb-invest.net and wb-bot.org, which kept normal operation for half a year.

Domain wb-invest.net and wb-bot.org registered in October 2018.

Faked cryptocurrency trading software “Worldbit-bot” based on the open-sourced “Qt Bitcoin Trader.”

Worldbit-bot runs under the domain of wb-invest.net and wb-bot.org.

The attackers targeted a large number of internal staff at cryptocurrency exchanges for the software promotion. The latest phishing attacks took place in January and March 2019.

According to China-based JohnWick Security, which has been assisting DragonEx in investigating its hacking incident, the customer service staff at DragonEx appear to have opened an installation package named wbbot.dmg from an unknown source. Analysis indicates a backdoor was embedded in the installation package, through which hackers acquired the internal staff’s authorization and then obtained the wallet private key.

The “Worldbit-bot” software operates in much the same manner, with the faked crypto trading software “Celas Trade Pro,” and was detected by the same team at 360 Security last August. Users of Bitfinex, Bitstamp, Bitmarket, BTCChina, GOC.io, Indacoin, OKCoin, WEX and Y0bit were susceptible to the threat at that time.

First, the process information is collected and encrypted:

System information is collected:

Malicious codes are executed and decrypted for file execution:

The security company is recommending that crypto exchanges be on the lookout for warning signs such as abnormal exchange earnings, tampered addresses of cold and hot wallets, large sum transfers and multiple account logins for coin withdrawal.

Lazarus is an infamous hacking group backed by North Korea. According to research, the group’s earliest attack may have been associated with “Operation Flame,” a large-scale DDOS attack on the South Korean government website in 2007. Lazarus is also alleged to have been the group behind the Sony Pictures hacking incident of 2014, the Bank of Bangladesh data breach of 2016 and the “Wannacry” ransomware attack that swept across the globe in 2017. Since 2017, the group has been expanding its targets of attack, increasingly aiming them at a variety of economic interests. In earlier attacks, the group mainly targeted the banking systems of traditional financial institutions. Now, it has begun to attack global cryptocurrency businesses and individuals.

As previously reported, Lazarus is purportedly responsible for $571 million of the $882 million in cryptocurrency that was stolen from exchanges from 2017 to 2018, almost 65 percent of the total amount. Out of 14 exchange attacks, five were attributed to the group, including the industry record-breaking $532 million NEM hack of Japan’s Coincheck.

This article originally appeared on Bitcoin Magazine.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Emerald Crypto (EMD) íà Currencies.ru

$ 0.0095806 (+7.58%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 2.35 %, 7d: -7.78 %
Cåãîäíÿ L: $0.0086651 - H: $0.0095806
Êàïèòàëèçàöèÿ $183.154k Rank 1690
Öåíà â ÷àñ íîâîñòè $ 0.0064331 (48.93%)

group software security crypto lazarus worldbit-bot cryptocurrency

group software → Ðåçóëüòàòîâ: 61


Ôîòî:

Surprise – the 3 biggest cybersecurity threats are all cryptocurrency miners

The three most prevalent threats plaguing the internet have been found to be cryptocurrency miners. In its latest analysis of the internet‘s most pressing malware hazards, cybersecurity group Check Point ranked the supposedly neutral Monero-mining script CoinHive in first place – for the thirteenth month in a row, reports ZDNet.

2019-1-14 19:49


Ethereum Developer ConsenSys Partners With AMD To Bolster Blockchain Industry

Although the crypto market has stagnated, the startups driving the blockchain boat have continued to forge ahead with their efforts. Reports indicate that ConsenSys, a key participant in the nascent Ethereum ecosystem, has partnered with a leading American multinational semiconductor conglomerate to produce blockchain-friendly hardware and software.

2019-1-6 05:00


South Korea Is Trialing Blockchain Voting — Here’s What That Means

South Korea will test out a new blockchain voting system this month, sources close to the developments have confirmed to Bitcoin Magazine. Developed by the country’s National Election Commission (NEC) and its Ministry of Science and ICT, the distributed ledger system is based on IBM’s Hyperledger Fabric and will be used to authenticate voters and save voting results in real time.

2018-12-4 21:41


Ôîòî:

Bitfury Acquires Minority Stake in Final Frontier, Aims To Expand Services

The Bitfury Group has acquired a minority stake in blockchain services firm Final Frontier. Both organizations are looking to utilize each other’s knowledge and experience in the traditional and digital finance spaces to potentially release a new line of financial products and services designed to assist professional investors in getting their hands on digital assets.

2018-11-14 00:53


Ôîòî:

BitFury $80M Funding Round Attracts Galaxy Digital’s Novogratz

Bitcoin mining infrastructure company BitFury Group has closed a private funding round worth $80 million from both global and cryptocurrency-focused investors. Cash To Fund ‘Hardware And Software’ Objectives In a press release November 6, BitFury, which is also rumored to be planning an IPO, revealed Mike Novogratz’s Galaxy Digital to be among the participants in the round, which was led by European venture capital firm Korelya Capital.

2018-11-7 11:00


Finance Giant Northern Trust Expands to Blockchain and Cryptocurrency

Northern Trust, the 486th largest corporation in the USA, has become the latest financial giant to expand operations into cryptocurrency and blockchain. As reported by Forbes, the 129-year-old institution now provides fund administration to a select group of hedge funds trading Bitcoin and Ethereum and incorporates blockchain-based software for managing private equity workflow.

2018-8-1 15:30


EOS PRO Blockchain Startup Announces EOSIO Distributed Network

EOS PRO, a blockchain-based startup, has announced the launch of its enterprise-grade distributed infrastructure offering using powerful, high speed EOSIO open source blockchain software. The group offers both public and private distributed networks maintained by permissioned, vetted enterprise-grade nodes equipped to provide business-ready security, scalability, performance and support. EOS PRO also offers a full suite […]

2018-8-1 11:26