{"id":77185,"date":"2024-04-24T11:30:39","date_gmt":"2024-04-24T15:30:39","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=77185"},"modified":"2024-04-24T11:31:43","modified_gmt":"2024-04-24T15:31:43","slug":"lazarus-group-reportedly-uses-linkedin-to-target-steal-assets","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/lazarus-group-reportedly-uses-linkedin-to-target-steal-assets\/","title":{"rendered":"Lazarus Group Reportedly Uses LinkedIn to Target, Steal Assets"},"content":{"rendered":"\n<p>Recent reports show that the <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-hackers-allegedly-stole-700m-crypto-in-2023.html\" target=\"_blank\" rel=\"noreferrer noopener\">North Korean Lazarus hacker group <\/a>targets vulnerable LinkedIn users with targeted malware attacks to take their assets.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"794\" height=\"532\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14.png\" alt=\"Lazarus Group Reportedly Uses LinkedIn to Target, Steal Assets\" class=\"wp-image-44885\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14.png 794w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14-300x201.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14-768x515.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14-150x101.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14-750x503.png 750w\" sizes=\"(max-width: 794px) 100vw, 794px\" \/><figcaption class=\"wp-element-caption\">Lazarus Group Reportedly Uses LinkedIn to Target, Steal Assets<\/figcaption><\/figure>\n\n\n\n<p>The revelation that hackers from the Lazarus group were posing as blockchain developers in the cryptocurrency industry on LinkedIn prompted the disclosure of the incident by the blockchain security analytics firm SlowMost.<\/p>\n\n\n\n<p>According to SlowMist, hackers stole sensitive employee credentials by granting access to their repository to execute pertinent code. The code fragments executed by the hacker comprise malevolent code that illicitly acquires sensitive data and assets.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"947\" height=\"546\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-152.png\" alt=\"Source: SlowMist\" class=\"wp-image-77192\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-152.png 947w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-152-300x173.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-152-768x443.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-152-750x432.png 750w\" sizes=\"(max-width: 947px) 100vw, 947px\" \/><figcaption class=\"wp-element-caption\">Source:\u00a0<a href=\"https:\/\/x.com\/im23pds\/status\/1782984061369405878\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SlowMist<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>Targeted assaults utilizing LinkedIn are not novel; in December 2023, a North Korean hacker group employed a comparable strategy by impersonating a Meta recruiter.<\/p>\n\n\n\n<p>The fraudulent recruiter requested that the targeted &#8220;applicants&#8221; obtain two coding challenges as part of the hiring process after establishing contact with them via LinkedIn. When executed on a work computer, these two coding files containing malware released a Trojan that enabled remote access.<\/p>\n\n\n\n<p>Lazarus has stolen cryptocurrency worth more than $3 billion. Since its inception in 2009, this highly infamous and well-coordinated hacking group has continued to target cryptocurrency companies despite facing numerous sanctions.<\/p>\n\n\n\n<p>Targeting and stealing funds creatively is a hallmark of Lazarus. In August 2023, the group stole $37 million from cryptocurrency payment company CoinPaid using fabricated job interviews. To compromise the CoinsPaid infrastructure, the hackers posed bogus high-paying employment offers to specific individuals.<\/p>\n\n\n\n<p>The organization has been responsible for several of the most significant heists in the cryptocurrency industry. The largest compromise was the Ronin Bridge in 2022, which yielded $625 million in misappropriated funds.<\/p>\n\n\n\n<p>Numerous reports indicate that the hacker group frequently launders its stolen funds back to North Korea via <a href=\"https:\/\/coinscreed.com\/staging\/swan-to-block-accounts-of-customers-using-crypto-mixing-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto mixing services<\/a>; these funds are reportedly used to finance the country's military operations.<\/p>\n\n\n\n<p>Although criminal groups frequently target cryptocurrency firms, the decentralized nature of blockchain prevents them from transferring funds. Cryptocurrency platforms often assist in the monitoring and blocking of identified threats.<\/p>\n\n\n\n<p>Huobi and Binance suspended at least $1.4 million in North Korea-related cryptocurrency assets in February 2023. Exchanges of cryptocurrencies similarly suspended assets valued at $63 million associated with the Harmony Bridge breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent reports show that the North Korean Lazarus hacker group targets vulnerable LinkedIn users with targeted malware attacks to take their assets. The revelation that hackers from the Lazarus group were posing as blockchain developers in the cryptocurrency industry on LinkedIn prompted the disclosure of the incident by the blockchain security analytics firm SlowMost. According [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":44885,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[6115,9168,4337],"class_list":["post-77185","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hackers-2","tag-lazarus-group","tag-north-korea"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-14.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/77185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=77185"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/77185\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/44885"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=77185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=77185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=77185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}