Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

North Korean cyberattacks on Brazilian fintech firms exposed

CointelegraphCointelegraph2024/06/13 12:07
By:Arijit Sarkar

Google Cloud’s threat intelligence department has discovered that North Korean government-backed cyber attackers are actively targeting Brazil’s cryptocurrency exchanges and fintech companies.

The June 13 Google threat intelligence report highlighted coordinated attempts to hijack, extort and defraud Brazilian individuals and organizations.

Source: Mandiant (part of Google Cloud)

While North Korean groups focus primarily on cryptocurrency firms, aerospace and defense and government entities, cyber criminals backed by the Chinese government prefer attacking only the government organizations and the energy sector in Brazil.

The plot behind cyberattacks in Brazil

The notorious North Korean cybercriminal group, Pukchong (also known as UNC4899), has targeted Brazilian citizens and organizations through the job market. They tricked unsuspecting job seekers into downloading malware onto their systems. According to the report:

“The project was a trojanized Python app for retrieving cryptocurrency prices that was modified to reach out to an attacker-controlled domain to retrieve a second stage payload if specific conditions were met.”

Similar malware attacks perpetrated by GoPix and URSA were also found actively targeting Brazilian crypto firms.

Government-backed phishing attacks targeting Brazil. Source: Google Cloud

Check out Cointelegraph’s guide to learn more about crypto malware and how to detect it .

Related: SEC fines NYSE parent company $10M for failing to report cyberattack

Attacks beyond borders

Recently, crypto wallet provider Trust Wallet asked Apple users to disable iMessage , citing “credible intel” of a zero-day exploit that could allow hackers to take control of users’ phones.

Source: Trust Wallet

A zero-day exploit is a cyberattack vector that takes advantage of an unknown or unaddressed security flaw in computer software, hardware or firmware.

Cybersecurity firm Kaspersky recently uncovered that North Korean hacking group Kimsuky reportedly utilized a “striking” new malware variant dubbed “Durian” to launch attacks on South Korean crypto firms.

Source: Kaspersky

“Durian boasts comprehensive backdoor functionality, enabling the execution of delivered commands, additional file downloads, and exfiltration of files,” wrote Kaspersky.

Additionally, Kaspersky noted that LazyLoad was also used by Andariel, a sub-group within fellow North Korean hacking consortium Lazarus Group — suggesting a “tenuous” connection between Kimsuky and the more notorious hacking group.

Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

エヌビディア株は7%上昇でも、AI関連ト―クンは大幅に下落

cointelegraph-jp-ai2024/07/12 12:58

チャットGPT使って作成されたミームコイン、時価総額が6億ドル超えに

cointelegraph-jp-ai2024/07/12 12:58

ブロックチェーンとAIの統合 イノベーションをもたらす=欧州委員会が報告書 

cointelegraph-jp-ai2024/07/12 12:58

Despite some losses, the SEC continues to fight crypto

Quick Take The Securities and Exchange Commission has had some notable legal and investigative losses in recent months, including a court sanction in Utah. However, legal experts and crypto commentators are split on whether the regulator is losing its attempt to classify nearly all cryptocurrencies as securities.

The Block2024/07/12 12:46

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
10048.2%
ROI
Total profit $51245.84
WhaleGo_YouTube
WhaleGo_YouTube
insight500/500
1338.92%
ROI
Total profit $3887.72

Bot copy trading

More
Morgee
Morgee
insight80/150
$17427.36
Total profit
Total subscriber profits $-223.07
GoldenEgg
GoldenEgg
insight149/150
$3416.37
Total profit
Total subscriber profits $-284.87