{"id":81174,"date":"2024-06-13T07:20:54","date_gmt":"2024-06-13T11:20:54","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=81174"},"modified":"2024-06-13T07:20:57","modified_gmt":"2024-06-13T11:20:57","slug":"north-korean-cyberattacks-expose-brazilian-fintech-firms","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/north-korean-cyberattacks-expose-brazilian-fintech-firms\/","title":{"rendered":"North Korean Cyberattacks Expose Brazilian Fintech Firms"},"content":{"rendered":"\n<p>Google Cloud's threat intelligence reveals North Korean-backed cyber attackers targeting Brazil's <a href=\"https:\/\/coinscreed.com\/staging\/cryptocurrency-exchanges-picking-the-right-platform-for-your-needs.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency exchanges<\/a> and fintech firms for hijacking, extortion, and fraud.<\/p>\n\n\n\n<p>The threat intelligence department of Google Cloud has identified that cyber assailants affiliated with the North Korean government are currently conducting an active campaign against Brazil's fintech companies and cryptocurrency exchanges.<\/p>\n\n\n\n<p>The coordinated endeavors to commandeer, extort, and defraud Brazilian individuals and organizations were emphasized in the June 13 Google threat intelligence report.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" width=\"886\" height=\"1024\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1-886x1024.webp\" alt=\"\" class=\"wp-image-81180\" style=\"width:744px;height:auto\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1-886x1024.webp 886w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1-259x300.webp 259w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1-768x888.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1-750x867.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/5b3778b1-80c8-45fe-9f06-7bd6a1cbd591-1.webp 1100w\" sizes=\"(max-width: 886px) 100vw, 886px\" \/><\/figure>\n\n\n\n<p>Although North Korean groups concentrate on cryptocurrency firms, aerospace and defense, and government entities, cyber criminals who are supported by the Chinese government prefer to target only the energy sector and government organizations in Brazil.<\/p>\n\n\n\n<p>The employment market has been the target of the notorious North Korean cybercriminal group, Pukchong (also known as UNC4899), which has targeted Brazilian citizens and organizations. They deceived job seekers into downloading malware onto their devices. In accordance with the report:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cThe project was a trojanized Python app for retrieving <a href=\"https:\/\/coinscreed.com\/staging\/cryptocurrency-prices-today.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency prices<\/a> that was modified to reach out to an attacker-controlled domain to retrieve a second stage payload if specific conditions were met.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Similarly, GoPix and URSA were observed to be actively targeting Brazilian crypto firms in malware attacks.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"914\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-1024x914.jpg\" alt=\"\" class=\"wp-image-81182\" style=\"width:831px;height:auto\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-1024x914.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-300x268.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-768x686.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-1536x1371.jpg 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-2048x1828.jpg 2048w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-1320x1178.jpg 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-750x670.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/61a306f5-17b6-4545-849c-46dad097946f-1-1140x1018.jpg 1140w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Trust Wallet, a crypto wallet provider, recently requested that Apple users disable iMessage. The company cited &#8220;credible intel&#8221; of a zero-day exploit that could enable hackers to take control of users' phones.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"529\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1-1024x529.webp\" alt=\"\" class=\"wp-image-81184\" style=\"width:763px;height:auto\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1-1024x529.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1-300x155.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1-768x397.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1-750x387.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/a36539ae-e638-407f-872e-6a1b5c934a7e-1.webp 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>A zero-day exploit is a type of cyberattack that exploits an unidentified or unaddressed security vulnerability in <a href=\"https:\/\/coinscreed.com\/staging\/hardware-vs-software-choosing-the-right-web3-wallet-for-your-needs.html\" target=\"_blank\" rel=\"noreferrer noopener\">computer software<\/a>, hardware, or firmware.<\/p>\n\n\n\n<p>Kaspersky, a cybersecurity firm, recently discovered that Kimsuky, a North Korean hacking group, employed a &#8220;striking&#8221; new malware variant known as &#8220;Durian&#8221; to initiate attacks on South Korean crypto firms.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"655\" height=\"548\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/c73c4001-9f0e-4e6c-86bf-987364b33981-1.webp\" alt=\"\" class=\"wp-image-81186\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/c73c4001-9f0e-4e6c-86bf-987364b33981-1.webp 655w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/c73c4001-9f0e-4e6c-86bf-987364b33981-1-300x251.webp 300w\" sizes=\"(max-width: 655px) 100vw, 655px\" \/><\/figure>\n\n\n\n<p>Kaspersky stated that Durian has a comprehensive backdoor functionality that allows for the implementation of commands, the downloading of additional files, and the exfiltration of files.<\/p>\n\n\n\n<p>Furthermore, Kaspersky observed that LazyLoad was also employed by Andariel, a sub-group within the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Lazarus_Group\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Lazarus Group<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, a North Korean hacking consortium, which implies a &#8220;tenuous&#8221; connection between Kimsuky and the more notorious hacking group.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Cloud&#8217;s threat intelligence reveals North Korean-backed cyber attackers targeting Brazil&#8217;s cryptocurrency exchanges and fintech firms for hijacking, extortion, and fraud. The threat intelligence department of Google Cloud has identified that cyber assailants affiliated with the North Korean government are currently conducting an active campaign against Brazil&#8217;s fintech companies and cryptocurrency exchanges. The coordinated endeavors [&hellip;]<\/p>\n","protected":false},"author":36,"featured_media":81187,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[19979,19978],"class_list":["post-81174","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-brazilian-fintech-firms","tag-north-korean-cyberattacks"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/06\/230324183106-north-korea-crypto-hacker.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/81174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=81174"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/81174\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/81187"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=81174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=81174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=81174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}