{"id":15166,"date":"2022-12-05T15:15:11","date_gmt":"2022-12-05T15:15:11","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/north-korean-lazarus-group-linked-to-new-cryptocurrency-hacking-scheme-security-bitcoin-news\/"},"modified":"2022-12-05T15:15:11","modified_gmt":"2022-12-05T15:15:11","slug":"north-korean-lazarus-group-linked-to-new-cryptocurrency-hacking-scheme-security-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/north-korean-lazarus-group-linked-to-new-cryptocurrency-hacking-scheme-security-bitcoin-news\/","title":{"rendered":"North Korean Lazarus Group Linked to New Cryptocurrency Hacking Scheme \u2013 Security Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n<\/div>\n<p><strong>The Lazarus group, a North Korean hacking organization previously linked to criminal activity, has been connected to a new attack scheme to breach systems and steal cryptocurrency from third parties. The campaign, which uses a modified version of an already existing malware product called Applejeus, uses a crypto site and even documents to gain access to systems.<\/strong><\/p>\n<h2 style=\"text-align: left;\">Modified Lazarus Malware Used Crypto Site as Facade<\/h2>\n<p>Volexity, a Washington D.C.-based cybersecurity firm, has linked Lazarus, a North Korean hacking group already sanctioned by the U.S. government, with a threat involving the use of a crypto site to infect systems in order to steal info and cryptocurrency from third parties.<\/p>\n<p>A blog post <a href=\"https:\/\/www.volexity.com\/blog\/2022\/12\/01\/buyer-beware-fake-cryptocurrency-applications-serving-as-front-for-applejeus-malware\/\" target=\"_blank\" rel=\"noopener\">issued<\/a> on Dec. 1 revealed that in June, Lazarus registered a domain called \u201cbloxholder.com,\u201d which would be later established as a business offering services of automatic cryptocurrency trading. Using this site as a facade, Lazarus prompted users to download an application that served as a payload to deliver the Applejeus malware, directed to steal private keys and other data from the users\u2019 systems.<\/p>\n<p>The same strategy has been used by Lazarus before. However, this new scheme uses a technique that allows the application to \u201cconfuse and slow down\u201d malware detection tasks.<\/p>\n<h2 style=\"text-align: left;\">Document Macros<\/h2>\n<p>Volexity also found that the technique to deliver this malware to final users changed in October. The method morphed to use Office documents, specifically a spreadsheet containing macros, a sort of program embedded in the documents designed to install the Applejeus malware in the computer.<\/p>\n<p>The document, identified with the name \u201cOKX Binance &amp; Huobi VIP fee comparision.xls,\u201d displays the benefits that each one of the VIP programs of these exchanges supposedly offers at their different levels. To mitigate this kind of attack, it is recommended to block the execution of macros in documents, and also scrutinize and monitor the creation of new tasks in the OS to be aware of new unidentified tasks running in the background. However, Veloxity did not inform on the level of reach that this campaign has attained.<\/p>\n<p>Lazarus was formally <a href=\"https:\/\/news.bitcoin.com\/us-government-expands-charges-against-north-korean-hackers-authorities-describe-them-as-the-worlds-leading-bank-robbers\/\" target=\"_blank\" rel=\"noopener\">indicted<\/a> by the U.S. Department of Justice (DOJ) in Feb. 2021, involving an operative of the group linked to a North Korean intelligence organization, the Reconnaissance General Bureau (RGB). Before that, in March 2020, the DOJ <a href=\"https:\/\/news.bitcoin.com\/north-korea-chinese-cryptocurrency\/\" target=\"_blank\" rel=\"noopener\">indicted<\/a> two Chinese nationals for aiding in the laundering of more than $100 million in cryptocurrency linked to Lazarus\u2019 exploits.<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/applejeus\/\">applejeus<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/bloxholder\/\">bloxholder<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto\/\">Crypto<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/data\/\">data<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/department-of-justice\/\">department of justice<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/indicment\/\">indicment<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/indictment\/\">indictment<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/lazarus\/\">Lazarus<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/malware\/\">Malware<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/payload\/\">payload<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/theft\/\">Theft<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/volexity\/\">volexity<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think about Lazarus\u2019 latest cryptocurrency malware campaign? Tell us in the comments section below.<\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/04\/img_20220427_085821_931.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/04\/img_20220427_085821_931.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/04\/img_20220427_085821_931.jpg 2x\" class=\"avatar avatar-150 photo\"\/><\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nSergio Goschenko <\/h6>\n<p class=\"article__body__author__info__about\">\nSergio is a cryptocurrency journalist based in Venezuela. He describes himself as late to the game, entering the cryptosphere when the price rise happened during December 2017. Having a computer engineering background, living in Venezuela, and being impacted by the cryptocurrency boom at a social level, he offers a different point of view about crypto success and how it helps the unbanked and underserved.<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<div class=\"disclaimer\">\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. <a href=\"https:\/\/bitcoin.com\">Bitcoin.com<\/a> does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<\/div>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/north-korean-lazarus-group-linked-to-new-cryptocurrency-hacking-scheme\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) The Lazarus group, a North Korean hacking organization previously linked to criminal activity, has been connected to a new attack scheme to breach systems and steal cryptocurrency from third parties. The campaign, which uses a modified version of an already existing malware product called Applejeus, uses a crypto [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":15167,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/15166"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=15166"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/15166\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/15167"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=15166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=15166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=15166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}