Report: Lazarus Hacker Group Adopts New Methods, Continues Targeting Crypto


0

Alleged North Korea-sponsored cybercrime group Lazarus is still targeting cryptocurrencies and adopting new tactics, according to a new report from cybersecurity and anti-virus company Kaspersky Lab published on March 26.

The report reveals that allegedly state-sponsored hacker group Lazarus has been active with a new operation since last November, wherein the group uses PowerShell that allows them to manage and control Windows and macOS malware. The Lazarus team has reportedly developed custom PowerShell scripts that interact with C2 malicious servers and execute commands from the operator.

C2 server script names, in their turn, are misrepresented as WordPress files, and other open source projects. Once the malware control session with the server is created, the malware is able to download and upload files, update malware configuration and collect basic host information, among others.

Kaspersky notes that the hackers are still targeting systems involved in the cryptocurrency and fintech industries, and advised players in those sectors to exercise caution:
 

“If you’re part of the booming cryptocurrency or technological startup industry, exercise extra caution when dealing with new third parties or installing software on your systems […] And never ‘Enable Content’ (macro scripting) in Microsoft Office documents received from new or untrusted sources…”

As previously reported, Lazarus is purportedly responsible for $571 million of the $882 million in cryptocurrency that was stolen from online exchanges from 2017–2018; almost 65 percent of the total sum. Out of 14 separate exchange breaches, five were attributed to the group, among them the industry record-breaking $532 million NEM hack of Japan’s Coincheck.

Earlier in March, Cointelegraph reported that North Korea has reportedly amassed $670 million in fiat and cryptocurrencies by conducting hacking attacks, wherein the hackers attacked overseas financial institutions from 2015 to 2018 and purportedly used blockchain “to cover their tracks.”


Like it? Share with your friends!

0

What's Your Reaction?

hate hate
0
hate
confused confused
0
confused
fail fail
0
fail
fun fun
0
fun
geeky geeky
0
geeky
love love
0
love
lol lol
0
lol
omg omg
0
omg
win win
0
win
COINTELEGRAPH

Choose A Format
Story
Formatted Text with Embeds and Visuals
Video
Youtube, Vimeo or Vine Embeds
List
The Classic Internet Listicles
Open List
Submit your own item and vote up for the best submission
Countdown
The Classic Internet Countdowns
Poll
Voting to make decisions or determine opinions
Ranked List
Upvote or downvote to decide the best list item
Personality quiz
Series of questions that intends to reveal something about the personality
Trivia quiz
Series of questions with right and wrong answers that intends to check knowledge
Meme
Upload your own images to make custom memes
Audio
Soundcloud or Mixcloud Embeds
Image
Photo or GIF
Gif
GIF format