Investors Hangout Stock Message Boards Logo
  • Mailbox
  • Favorites
  • Boards
    • The Hangout
    • NASDAQ
    • NYSE
    • OTC Markets
    • All Boards
  • Whats Hot!
    • Recent Activity
    • Most Viewed Boards
    • Most Viewed Posts
    • Most Posted
    • Most Followed
    • Top Boards
    • Newest Boards
    • Newest Members
  • Blog
    • Recent Blog Posts
    • Recently Updated
    • News
    • Stocks
    • Crypto
    • Investing
    • Business
    • Markets
    • Economy
    • Real Estate
    • Personal Finance
  • Market Movers
  • Interactive Charts
  • Login - Join Now FREE!
  1. Home ›
  2. Stock Message Boards ›
  3. User Boards ›
  4. SHEEPWOLF'S $1,000,000.00 JOURNEY Message Board

New Report: North Korean Hackers Stole Funds From

Message Board Public Reply | Private Reply | Keep | Replies (1)                   Post New Msg
Edit Msg () | Previous | Next


Post# of 106743
(Total Views: 262)
Posted On: 01/21/2018 12:28:46 PM
Posted By: dw
New Report: North Korean Hackers Stole Funds From South Korean Cryptocurrency Exchanges

12078 Total views 288 Total shares
ANALYSIS
US cybersecurity firm Recorded Future has released a new report linking Lazarus, a North Korean hacking group, to various South Korean cryptocurrency exchange hacking attacks and security breaches.

In a report entitled “North Korea Targeted South Korean Cryptocurrency Users and Exchange in Late 2017 Campaign,” the firm’s researchers stated that the same type of malware used in the Sony Pictures security breach and WannaCry ransomware attack was utilized to target Coinlink, a South Korea-based cryptocurrency exchange.

“North Korean government actors, specifically Lazarus Group, continued to target South Korean cryptocurrency exchanges and users in late 2017, before Kim Jong Un’s New Year’s speech and subsequent North-South dialogue. The malware employed shared code with Destover malware, which was used against Sony Pictures Entertainment in 2014 and the first WannaCry victim in February 2017,” the report read.

$7 mln stolen from Bithumb
In February 2017, Bithumb, the second largest cryptocurrency exchange in the global market by daily trading volume, fell victim to a security breach that led to the loss of around $7 mln of user funds, mostly in Bitcoin and Ethereum’s native cryptocurrency Ether.

The report released by Recorded Future noted that the $7 mln Bithumb security breach has been linked to North Korean hackers. Insikt Group researchers, a group of cybersecurity researchers that closely track the activities of North Korean hackers regularly, revealed that Lazarus Group, in particular, has used a wide range of tools from spear phishing attacks to malware distribution through communication platforms to gain access to cryptocurrency wallets and accounts.

Insikt Group researchers disclosed that Lazarus Group hackers initiated a massive malware campaign in the fall of 2017 and since then, North Korean hackers have focused on spreading malware by attaching files containing fraudulent software to gain access to individual devices.

One method Lazarus Group employed was the distribution of Hangul Word Processor (HWP) files through email, the South Korea equivalent of Microsoft Word documents, with malware attached. If any cryptocurrency user downloads the malware, it autonomously installs itself and operates in the background, taking control of or manipulating data stored within the specific device.



“By 2017, North Korean actors had jumped on the cryptocurrency bandwagon. The first known North Korean cryptocurrency operation occurred in February 2017, with the theft of $7 mln (at the time) in cryptocurrency from South Korean exchange Bithumb. By the end of 2017, several researchers had reported additional spear phishing campaigns against South Korean cryptocurrency exchanges, numerous successful thefts, and even Bitcoin and Monero mining,” Insikt Group researchers wrote.

Motivation of North Korean hackers
Prior to the release of Recorded Future’s report, several other cybersecurity firms had accused North Korean hacking groups of targeting South Korean cryptocurrency trading platforms with sophisticated malware and phishing attack tools.

Researchers at FireEye linked six targeted cyber attacks against South Korean cryptocurrency exchanges to state-financed hackers based in North Korea. Most recently, as Cointelegraph reported, police investigators and the Korea Internet and Security Agency initiated a full investigation into a security breach that led to the bankruptcy of YouBit, a South Korean cryptocurrency trading platform.

At the time, local investigators stated that they have found evidence to link the YouBit security breach to North Korean hackers. FireEye senior analyst Luke McNamara also told Bloomberg that similar tools widely utilized by North Korean hackers were employed in the YouBit hacking attack.

“This an adversary that we have been watching become increasingly capable and also brazen in terms of the targets that they are willing to go after. This is really just one prong in a larger strategy that they seem to be employing since at least 2016, where they have been using capability that has been primarily used for espionage to actually steal funds.”

Follow us on Facebook

Bitcoin News
Cryptocurrencies
Cryptocurrency Exchange
South Korea
North Korea
Tradings
Bithumb
Hackers


(1)
(0)








Investors Hangout

Home

Mailbox

Message Boards

Favorites

Whats Hot

Blog

Settings

Privacy Policy

Terms and Conditions

Disclaimer

Contact Us

Whats Hot

Recent Activity

Most Viewed Boards

Most Viewed Posts

Most Posted Boards

Most Followed

Top Boards

Newest Boards

Newest Members

Investors Hangout Message Boards

Welcome To Investors Hangout

Stock Message Boards

American Stock Exchange (AMEX)

NASDAQ Stock Exchange (NASDAQ)

New York Stock Exchange (NYSE)

Penny Stocks - (OTC)

User Boards

The Hangout

Private

Global Markets

Australian Securities Exchange (ASX)

Euronext Amsterdam (AMS)

Euronext Brussels (BRU)

Euronext Lisbon (LIS)

Euronext Paris (PAR)

Foreign Exchange (FOREX)

Hong Kong Stock Exchange (HKEX)

London Stock Exchange (LSE)

Milan Stock Exchange (MLSE)

New Zealand Exchange (NZX)

Singapore Stock Exchange (SGX)

Toronto Stock Exchange (TSX)

Contact Investors Hangout

Email Us

Follow Investors Hangout

Twitter

YouTube

Facebook

Market Data powered by QuoteMedia. Copyright © 2025. Data delayed 15 minutes unless otherwise indicated (view delay times for all exchanges).
Analyst Ratings & Earnings by Zacks. RT=Real-Time, EOD=End of Day, PD=Previous Day. Terms of Use.

© 2025 Copyright Investors Hangout, LLC All Rights Reserved.

Privacy Policy |Do Not Sell My Information | Terms & Conditions | Disclaimer | Help | Contact Us