o3n [ozone] blockchain layer

Blockchain source

Menu
  • Cybersecurity services
Menu

North Korean Hacker Group Modifies Crypto-Stealing Malware

Posted on January 9, 2020 by nbelov

The allegedly North Korea-sponsored hackers known as Lazarus have deployed new viruses to steal cryptocurrency.

The Lazarus hacker group, which is allegedly sponsored by the North Korean government, has deployed new viruses to steal cryptocurrency.

Major cybersecurity firm Kaspersky reported on Jan. 8 that Lazarus has doubled down its efforts to infect both Mac and Windows users’ computers.

The group had been using a modified open-source cryptocurrency trading interface called QtBitcoinTrader to deliver and execute malicious code in what has been called “Operation AppleJeus,” as Kaspersky reported in late August 2018. Now, the firm reports that Lazarus has started making changes to the malware.

Kaspersky identified a new macOS and Windows virus named UnionCryptoTrader, which is based on previously detected versions. Another new malware, targeting Mac users, is named MarkMakingBot. The cybersecurity firm noted that Lazarus has been tweaking MarkMakingBot, and speculates that it is “an intermediate stage in significant changes to their macOS malware.”

Researchers also found Windows machines that were infected through a malicious file called WFCUpdater but were unable to identify the initial installer. Kaspersky said that the infection started from .NET malware that was disguised as a WFC wallet updater and distributed through a fake website. 

The malware infected the PCs in several stages before executing the group’s commands and permanently installing the payload.

Attackers may have used Telegram to spread malware

Windows versions of UnionCryptoTrader were found to be executed from Telegram’s download folder, leading researchers to believe “with high confidence that the actor delivered the manipulated installer using the Telegram messenger.” 

A further reason to believe that Telegram was used to spread malware is the presence of a Telegram group on the fake website. The interface of the program featured a graphical interface showing the price of Bitcoin (BTC) on several cryptocurrency exchanges.

UnionCryptoTrader user interface screenshot

UnionCryptoTrader user interface screenshot. Source: Kaspersky

The windows version of UnionCryptoTrader initiates a tainted Internet Explorer process, which is then employed to carry out the attacker’s commands. Kaspersky detected instances of the malware described above in the United Kingdom, Poland, Russia and China. The report reads:

“We believe the Lazarus group’s continuous attacks for financial gain are unlikely to stop anytime soon. […] We assume this kind of attack on cryptocurrency businesses will continue and become more sophisticated.”

Lazarus has been known to target crypto users for a long time. In October 2018, Cointelegraph reported that the group had stolen a staggering $571 million in cryptocurrencies since early 2017.

In March 2019, reports by Kaspersky suggested that the group’s efforts in targeting cryptocurrency users were still ongoing and its tactics were evolving. Furthermore, the group’s macOS virus was also enhanced in October last year.

Source: Cointelegraph https://cointelegraph.com/

Recent Posts

  • Blockchain Identity Management Market 2022-2028: Featuring Key Players Amazon Web Services Inc., Microsoft, IBM & Others – ResearchAndMarkets.com – Business Wire July 1, 2022
  • $23.3 Billion Global Web 3.0 Blockchain Market Growth with GAGR of 41.6% 2022-2028 | The Benefits such as Improved Privacy & Secure Network Driving the Market – GlobeNewswire July 1, 2022
  • Blockchain Bites: A$DC used in Carbon Credit purchase; Three Arrows to be liquidated in BVI; Laying the first blocks of US crypto regulatory reform; Hong Kong to licence VASPs and regulate market conduct – Lexology July 1, 2022
  • Minima's cooperative Blockchain network reaches 120000 complete nodes – IBS Intelligence July 1, 2022
  • 'Global Economy Can Be Fixed By Digital Transformation And Blockchain Technology' – Entrepreneur July 1, 2022
  • Global Blockchain Technology in Healthcare Market Report 2022-2027: Rising Application of Blockchain in Healthcare Claims and Billing Driving Growth – ResearchAndMarkets.com – Business Wire July 1, 2022
  • Laura K. Inamedinova on Maximizing Press for Blockchain Projects – Crypto Mode July 1, 2022
  • Coinbase denies reports of selling customer data to the US government July 1, 2022
  • Not giving up: VanEck refiles with SEC for spot Bitcoin ETF July 1, 2022
  • Bitcoin price: June close barely beats 2017 high as Coinbase Premium flips positive July 1, 2022
  • Key Takeaways | Crypto, Smart Contracts and Blockchain—Execution and Innovation – Lexology July 1, 2022
  • MakerDAO members shoot down proposal for more centralization July 1, 2022
  • OwlTing enlists Dow Jones database to enhance blockchain transaction security – DIGITIMES July 1, 2022
  • Multisigs mean funds in bridges are 'one small slipup' from being hacked July 1, 2022
  • Hundreds of Bored Ape owners sign up to hire out their NFTs to brands July 1, 2022
  • Better days ahead with crypto deleveraging coming to an end: JPMorgan July 1, 2022
  • Ethereum fork a success as Sepolia testnet gears up to trial the Merge July 1, 2022
  • Worst quarter in 11 years as Bitcoin price and activity plunges July 1, 2022
  • Societe Generale – FORGE selects METACO to manage blockchain asset capabilities – CryptoNinjas July 1, 2022
  • BnkToTheFuture unveils 3 proposals to rescue Celsius from oblivion July 1, 2022
  • EU agrees on MiCA regulation to crack down on crypto and stablecoins July 1, 2022
  • Kalima – A new way to collect, protect and monetize data using Blockchain for IoT – CryptoNinjas July 1, 2022
  • FTX Abandoned Discussions to Celsius Network Acquisition – Report – Blockchain.News July 1, 2022
  • Xinghuo BIF and Zetrix Jointly Introduce Web3 Services: Blockchain Identity/Verifiable Credentials and Contract Signing – GlobeNewswire July 1, 2022
  • Rewards4Earth plans to roll out crypto rewards to 1000 sports clubs in Australia July 1, 2022
  • Klever goes live with Mainnet of its native blockchain – FinanceFeeds July 1, 2022
  • CoinAgenda Announces First Round of Speakers for Ninth Annual Las Vegas and Sixth Annual Puerto Rico Web3, Blockchain and Crypto Conferences – GlobeNewswire June 30, 2022
  • Blockchain.com Cooperating With Investigations Into Three Arrows – Bloomberg June 30, 2022
  • NFTs to appear on Facebook, cross-post with Instagram as Meta Web3 expansion continues June 30, 2022
  • Former Monero maintainer Riccardo 'Fluffypony' Spagni to surrender for South Africa extradition June 30, 2022

Ad

Ad

©2022 o3n [ozone] blockchain layer | WordPress Theme by Superbthemes.com