Notorious Lazarus Group Attempted Cyber-Attack, Alleges deBridge Co-Founder

0

[ad_1]

The “Lazarus Group,” a notorious North Korea-backed hacking syndicate, has been identified as the culprit of an attempted cyber-attack on deBridge Finance. The co-founder of the cross-chain protocol and project lead, Alex Smirnov, alleged that the attack vector was via an email wherein several team members received a PDF file named “New Salary Adjustments” from a spoofed address that mirrored the exec’s own.

While deBridge Finance managed to thwart the phishing attack, Smirnov warned that the fraudulent campaign is likely widespread targeting Web3-focussed platforms.

Attempted Attack on deBridge

According to a long Twitter thread by the exec, most team members immediately flagged the suspicious email, but one downloaded and opened the file. This helped them investigate the attack vector and understand its consequences.

Smirnov further explained that macOS users are safe, as opening the link on a Mac would lead to a zip archive with the normal PDF file Adjustments.pdf. On the other hand, Windows systems are not immune to the dangers. Instead, Windows users will be directed to an archive with a dubious password-protected pdf with the same name and an additional file named Password.txt.lnk.

The text file would essentially infect the system. As such, a lack of anti-virus software will help the malicious file to penetrate the machine and will be saved in the autostart folder, following which a simple script will start sending repetitive requests to communicate with the attacker in order to receive instructions.

“The attack vector is as follows: user opens a link from email -> downloads & opens archive -> tries to open PDF, but PDF asks for a password -> user opens password.txt.lnk and infects the whole system.”

The co-founder then urged the firms and their employees to never open email attachments without verifying the sender’s full email address and to have an internal protocol for how teams share attachments.

“Please stay SAFU and share this thread to let everyone know about potential attacks.”

Lazarus Attackers Targeting Crypto

The state-sponsored North Korean hacking groups are infamous for conducting financially motivated attacks. Lazarus, for one, carried out many high-profile attacks on crypto exchanges, NFT marketplaces, and individual investors with significant holdings. The latest attack appears to have a significant resemblance to previous ones conducted by the hacking syndicate.

Amid the COVID-19 outbreak, cyber-crimes led by Lazarus saw a massive uptrend. More recently, the group stole over $620 million from Axie Infinity’s Ronin bridge earlier this year.

In fact, reports also reveal that the country’s cyber program is large and well-organized despite being economically isolated from the rest of the world. As per multiple US government sources, these entities have also adapted to Web3 and are currently targeting the decentralized finance space.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
tron
TRON (TRX) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
monero
Monero (XMR) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
rain
Rain (RAIN) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
Shares