• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
north korea's lazarus group suspected in $31 million coinex heist

North Korea’s Lazarus Group Suspected in $31 Million CoinEx Heist

You are here: Home / General Cyber Security News / North Korea’s Lazarus Group Suspected in $31 Million CoinEx Heist
September 17, 2023

The North Korea-affiliated Lazarus Group has stolen almost $240 million in cryptocurrency given that June 2023, marking a major escalation of its hacks.

In accordance to a number of stories from Certik, Elliptic, and ZachXBT, the notorious hacking group is said to be suspected at the rear of the theft of $31 million in digital belongings from the CoinEx exchange on September 12, 2023.

The crypto heist aimed at CoinEx adds to a string of latest attacks focusing on Atomic Wallet ($100 million), CoinsPaid ($37.3 million), Alphapo ($60 million), and Stake.com ($41 million).

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“Some of the money stolen from CoinEx ended up sent to an address which was made use of by the Lazarus team to launder resources stolen from Stake.com, albeit on a distinctive blockchain,” Elliptic mentioned. “Adhering to this, the money were being bridged to Ethereum, working with a bridge previously employed by Lazarus, and then despatched back to an handle regarded to be managed by the CoinEx hacker.”

The blockchain analytics firm reported the latest attacks are an indicator that the adversarial collective is shifting its target from decentralized products and services to centralized kinds, the latter of which ended up its targets prior to 2020.

The pivot is probable enthusiastic by enhancements in good contract auditing and enhancement benchmarks in the DeFi area and increased access offered by centralized exchanges by using social engineering attacks.

Million CoinEx Heist

The advancement will come as the leader of the sanctions-hit nation, Kim Jong Un, frequented Russia for what is thought to be an arms deal, even as it fired two quick-selection ballistic missiles towards its jap seas previously in the 7 days.

North Korea has leveraged cryptocurrency thefts as a way to get all-around sanctions and fund its weapons applications. An additional profits generation channel is its use of freelance IT employees abroad utilizing fraudulent identification files that obscure their genuine nationality.

“In recent several years, there has been a marked rise in the size and scale of cyber attacks from cryptocurrency-linked enterprises by North Korea,” TRM Labs stated in June 2023. “This has coincided with an obvious acceleration in the country’s nuclear and ballistic missile packages.”

Approaching WEBINARIdentity is the New Endpoint: Mastering SaaS Security in the Fashionable Age

Dive deep into the long term of SaaS security with Maor Bin, CEO of Adaptive Defend. Explore why identity is the new endpoint. Secure your location now.

Supercharge Your Competencies

The Lazarus Team and its sub-clusters as very well as other hacking outfits connected to the state have been on a rampage in modern months, orchestrating a range of destructive functions, like computer software supply chain attacks focusing on companies this kind of as 3CX and JumpCloud as perfectly as open up-source repositories for JavaScript and Python.

In a publish-mortem of the hack, CoinsPaid disclosed that phony recruiters from crypto businesses contacted its employees through LinkedIn and many Messengers with beneficial salaries and trick them into “installing the JumpCloud Agent or a specific software to full a technological undertaking,” a campaign recognized as Procedure Desire Occupation.

Discovered this posting fascinating? Observe us on Twitter  and LinkedIn to go through much more exclusive content we article.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «tiktok faces massive €345 million fine over child data violations TikTok Faces Massive €345 Million Fine Over Child Data Violations in E.U.
Next Post: Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks financially motivated unc3944 threat actor shifts focus to ransomware attacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.