CandleFocus

North Korea's Lazarus Group now using crypto gifts to breach security defenses

The North Korean-linked Lazarus Group has implemented a new strategy to breach cryptocurrency firms by sending cryptocurrency to their targets as part of a social engineering scheme. The group aims to gain the victim's trust by making direct payments in advance, with the amount reaching thousands of dollars. By appearing legitimate, the attackers increase the chances of victims complying with their requests. The hackers establish contact with employees of crypto firms and send them digital assets to gain credibility. Once trust is established, victims are tricked into executing backdoor-embedded malicious code. The incident highlights the need for crypto firms to strengthen internal security measures and educate employees on recognizing deceptive tactics. The Lazarus Group's activities decreased after a summit between Russian President Vladimir Putin and North Korean leader Kim Jong Un in late June 2024, but this new approach suggests a potential resurgence of their attacks.

Related News