The US Department of Justice and the FBI announced it has seized about $500,000 in…
Now, the FBI has officially confirmed that the conclusions of the security experts were correct: North Korean hackers from the Lazarus (APT38) groups were behind this attack.
According to law enforcement, North Korean hack groups are stealing and laundering virtual currency to support government programs to build ballistic missiles and weapons of mass destruction.
The link between Lazarus and the robbery was revealed due to one of the attempts to launder the stolen assets, undertaken by hackers last week. On January 13, 2023, attackers reportedly attempted to transfer 41,000 ETH (about $63.5 million) through Railgun, which is being used as a replacement for the recently sanctioned Tornado Cash cryptocurrency mixer, before converting the funds into BTC and withdrawing to multiple addresses on three cryptocurrency exchanges.
Money laundering scheme
It was found that about 350 addresses are under the direct control of Lazarus, and part of the stolen funds was eventually frozen on the accounts of the Binance and Huobi exchanges. However, the bulk of the assets still remain under the control of hackers in these wallets:
According to the authorities, during this attack, as well as during the attack on Axie Infinity and the Ronin sidechain, hackers used the TraderTraitor malware, which was aimed at compromising the machines of employees of target companies. This malware is usually delivered to victims through social engineering (via email or private messages) disguised as high-paying job offers.
The malware is written in cross-platform JavaScript that runs inside Electron and is capable of deploying secondary payloads on both Windows and macOS systems (depending on the platform used by the compromised employee).
Let me also remind you that the media wrote that Lazarus Hack Dell Devices Through Vulnerable Driver.
Chernars.com is a domain that tries to force you into subscribing to its browser notifications…
Eclipse-adblocker.pro is a site that tries to trick you into clik to its browser notifications…
Initiateadvancedcompletelythe-file.top is a site that tries to force you into subscribing to its browser notifications…
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…
Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…
Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…