朝鲜黑客Lazarus Group 6年窃取30亿

币圈资讯 阅读:33 2024-04-22 12:08:32 评论:0



APP下载   全球官网 大陆官网



APP下载   官网地址



APP下载   官网地址


近日,根据网络安全公司Recorded Future发布的一份报告显示,与朝鲜有关的黑客组织 Lazarus Group在过去6年中窃取了30亿美元加密货币。

报告称,仅在2022年,Lazarus Group就掠夺了17亿美元的加密货币,很可能为朝鲜项目提供资金。

区块链数据分析公司Chainaanalysis 表示,其中11亿美元是从DeFi平台被盗的。美国国土安全部9月份发布报告称,作为其分析交换计划 (AEP) 的一部分,也强调了 Lazarus对 DeFi 协议的利用。

Lazarus Group 的专长是资金盗窃。2016年,他们入侵了孟加拉国中央银行,窃取了8100万美元。2018年,他们攻击了日本加密货币交易所Coincheck,盗走了5.3亿美元,并攻击了马来西亚中央银行,窃取了3.9亿美元。












2023年7月12日,美国企业软件公司JumpCloud宣布,一名朝鲜支持的黑客已经进入其网络。Mandiant研究人员随后发布一份报告,指出负责此次攻击的团体是UNC4899,很可能对应着「TraderTraitor」,一个专注于加密货币的朝鲜黑客组织。截至2023年8月22日,美国联邦调查局(FBI)发布通告称,朝鲜黑客组织涉及Atomic Wallet、Alphapo和CoinsPaid的黑客攻击,共窃取1.97亿美元的加密货币。这些加密货币的窃取使得朝鲜政府能够在严格的国际制裁下继续运作,并资助其高达50%的弹道导弹计划的成本。







2022年归属于APT38的显著攻击包括Ronin Network跨链桥(损失6亿美元)、Harmony桥(损失1亿美元)、Qubit Finance桥(损失8000万美元)和Nomad桥(损失1.9亿美元)。这4次攻击特别针对这些平台的跨链桥。跨链桥连接了2个区块链,允许用户将一种加密货币从一个区块链发送到另一个包含不同加密货币的区块链。

2022年10月,日本警察厅宣布Lazarus Group针对在日本运营的加密货币行业的公司进行了攻击。虽然没有提供具体细节,但声明指出,一些公司遭到了成功的入侵,并且加密货币被窃取。

2023年1月至8月间,APT38据称从Atomic Wallet(2次攻击共1亿美元损失)、AlphaPo(2次攻击共6000万美元损失)和CoinsPaid(3700万美元损失)窃取了2亿美元。同样在1月份,美国FBI证实,APT38在窃取Harmony的Horizon桥虚拟货币方面损失了1亿美元。



以下是Insikt Group提出的防范建议,以防止朝鲜网络攻击针对加密货币用户和公司的攻击行为:













The author's carbon chain value recently, according to a report released by a network security company, hackers related to North Korea have stolen hundreds of millions of dollars of cryptocurrency in the past year. The report said that cryptocurrency robbed hundreds of millions of dollars in 2008 alone, which is likely to provide funds for North Korea projects. Blockchain data analysis company said that hundreds of millions of dollars of them were stolen from the platform. The US Department of Homeland Security released a report in January, saying that as part of its analysis and exchange plan, it also emphasized that the specialty of using the agreement was stealing funds in 2008. Invaded the Central Bank of Bangladesh and stole $10,000 a year. They attacked the Japanese cryptocurrency exchange and stole $100 million, and attacked the Central Bank of Malaysia and stole $100 million. The essence of the report is for your reference. Since 2000, North Korea has targeted the cryptocurrency industry for cyber attacks, stealing cryptocurrency worth more than $100 million. Before that, North Korea hijacked the network and stole funds from financial institutions. This activity has attracted close attention from international institutions. And investment has improved its own network security defense. When cryptocurrency became popular and became the mainstream in, North Korean hackers turned their stealing target from traditional finance to this new digital finance. First, they aimed at the Korean cryptocurrency market, and then their influence expanded on a global scale. Only in, North Korean hackers were accused of stealing cryptocurrency worth about 100 million dollars, which is equivalent to about the size of North Korea's domestic economy or its military budget, and this figure is almost twice the annual export value of North Korea, according to the website. The data show that North Korea's export in that year was US$ 100 million. The operation mode of North Korean hackers stealing cryptocurrencies in the encryption industry is usually similar to that of traditional cyber crimes that use encryption mixers to cross-chain transactions and legal money. However, because there is a country behind them, the theft can expand its own operation scale, which is impossible for traditional cyber criminal gangs. According to the data, there are about stolen cryptocurrencies in the encryption industry, and the goals of North Korean hackers are not good. Limited to individual users of exchanges, venture capital firms and other technologies and agreements have been attacked by North Korean hackers. All these institutions and individuals operating in the industry may become potential targets of North Korean hackers, so that the North Korean government can continue to operate and raise funds. Any user, exchange operator and founder of start-ups working in the encryption industry should be aware of the possible targets of hacking. Traditional financial institutions should also pay close attention to the activities of North Korean hackers. Once the cryptocurrency is stolen and converted into legal tender, North Korean hackers will transfer funds between different accounts to cover up the source. Usually, the stolen identity and the modified photos will be used to bypass the verification. Any personally identifiable information that becomes the victim of the invasion related to the North Korean hacker team may be used to register accounts to complete the money laundering process of stealing cryptocurrency. Therefore, companies operating cryptocurrency and outside the traditional financial industry should also be alert to the activities of North Korean hacker groups and their Whether data or infrastructure is used as a springboard for further invasion, because most of the intrusions by North Korean hackers begin with social engineering and phishing activities, some organizations should train employees to monitor such activities and implement strong multi-factor authentication, such as standard password-free authentication. North Korea clearly regards the continuous theft of cryptocurrency as the main source of income to fund its own military and weapons projects, although it is not clear how much of the stolen cryptocurrency is directly used to fund bombs. Missile launches, but it is obvious that the number of cryptocurrencies stolen and the number of missile launches have increased greatly in recent years. Without stricter regulations, network security requirements and investment in cryptocurrency companies, North Korea will almost certainly continue to use cryptocurrency industry as a source of support for the country's additional income. On April, American enterprise software company announced that a hacker supported by North Korea had entered its network, and then released a report stating that the group responsible for the attack was likely to be right. In response to a North Korean hacker organization focusing on cryptocurrencies, the FBI issued a notice as of March, saying that the hacker attacks involved by the North Korean hacker organization had stolen hundreds of millions of dollars of cryptocurrencies. The theft of these cryptocurrencies enabled the North Korean government to continue to operate under strict international sanctions and funded its high cost of ballistic missile program. In, North Korean hackers invaded South Korean exchanges and the cryptocurrencies stolen at that time were worth about 10,000 dollars. It was also reported that the personal customers of users in March were worth about 10,000 dollars. After the identity information was leaked, cryptocurrency users also became the target of attack. In addition to stealing cryptocurrency, North Korean hackers also learned how to mine cryptocurrency. In September, Kaspersky Lab researchers discovered a mining software, which was installed in the invasion month. Researchers at the Korea Institute of Financial Security announced that North Korean organizations invaded an undisclosed company server in the summer of 2008 and used it to mine about Monroe coins worth about US dollars at that time. The security researchers continued to report on North Korea's black. New cyber attacks on cryptocurrency industry by customers North Korean hackers attacked cryptocurrency exchanges in the United States, Europe, Japan, Russia and Israel, and used the method of initial contact as the target. Last year was the most productive year for cryptocurrency industry in North Korea, and North Korean hackers invaded at least one cryptocurrency institution and stole cryptocurrency worth hundreds of millions of dollars. In addition, North Korean hackers began to target counterfeit coins, including tokens, and researchers confirmed that there were still hundreds of millions of dollars worth of Canadian dollars since. The notable attacks attributed to the year when cryptocurrency is to be cashed include the loss of $ billion across the chain bridge, $ billion across the bridge and $ billion across the bridge. This attack is especially aimed at the cross-chain bridge of these platforms, which connects a blockchain to allow users to send one cryptocurrency from one blockchain to another with different cryptocurrencies. In September, the Japanese police announced that it had attacked companies operating in the cryptocurrency industry in Japan, although it did not provide specific details, but the statement pointed out that Some companies were successfully invaded and cryptocurrency was stolen. It is said that from January to October, a total of $100 million was lost from the second attack, and a total of $10,000 was lost and $100,000 was stolen. Similarly, in January, the United States confirmed that it lost $100 million in stolen bridge virtual currency. In the attack in June, the operator may pretend to be an employee specially targeted by the recruiter and sent a recruitment email and message, indicating that it took months to try to gain access to its network. The following are some preventive suggestions to prevent North Korea from cyber attacks and enable multiple identities against cryptocurrency users and companies. 比特币今日价格行情网_okx交易所app_永续合约_比特币怎么买卖交易_虚拟币交易所平台


注册有任何问题请添加 微信:MVIP619 拉你进入群

弹窗与图片大小一致 文章转载注明 网址:https://netpsp.com/?id=62734




APP下载   全球官网 大陆官网



APP下载   官网地址



APP下载   官网地址




  全球官网 大陆官网











