Skip to main content

North Korean hackers target cryptocurrency with malware

posted onNovember 8, 2024
by l33tdawg
Flickr
Credit: Flickr

SentinelLabs has identified a new cyber campaign by the North Korean state-sponsored threat actor group BlueNoroff, targeting cryptocurrency-related businesses with multi-stage malware.

The campaign, titled 'Hidden Risk', involves the use of email and PDF lures containing fake crypto news headlines to infiltrate organisations within the crypto industry. SentinelLabs attributes this activity to the same actor responsible for previous attacks such as RustDoor/ThiefBucket and RustBucket campaigns.

North Korean-affiliated threat actors have long targeted cryptocurrency businesses, aiming either to steal funds or install backdoor malware. The latest campaign was first observed in October 2024; however, evidence suggests it may have begun as early as July 2024. The malware is delivered via phishing emails disguised as links to PDFs on crypto-related topics such as "Hidden Risk Behind New Surge of Bitcoin Price" and "Altcoin Season 2.0-The Hidden Gems to Watch."

Source

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th