North Korean Hackers, Lazarus group, tied to the Atomic Wallet breach

TL;DR Breakdown

  • Elliptic Firm and its Investigative arm say that users of Atomic Wallet have fallen victim to Lazarus, the notorious North Korean cybercrime group. 
  • So far, $35 million has been stolen in bitcoin, ether, tether, Dogecoin, Litecoin, BNB coin, polygon, and Tron-based USDT.
  • The stolen assets are being laundered using specific services, such as the Sinbad mixer, which has also been used to launder the proceeds of Lazarus Group Hacks in the past.

Elliptic, a blockchain intelligence firm, said in a blog post on Tuesday that users of Atomic Wallet may have fallen victim to Lazarus, the notorious North Korean cybercrime group. Reportedly, illegal funds from the $35 million Atomic Wallet hack have been transferred to a crypto aggregator that is favored by North Korea’s most notorious cyber-hacking group.

The Lazarus Group financial terror hits the crypto industry hard

Lazarus Group is a North Korean cybercrime organization known for its cyber exploits, and it has been blamed for a number of attacks since 2010. The entity is thought to be funded by the North Korean government and consists of an unknown number of hackers. It has launched an increasing number of attacks through its various subgroups, including StoneFly, AndAriel, and BlueNoroff.

Since 2017, when it attacked South Korean crypto investors with Bitcoin and Monero holdings, the criminal group has terrorized the crypto community by using autonomous means of distributing new sorts of computer viruses that expose flaws in well-known software systems. Previously, Lazarus Group was notorious for conducting cyber espionage campaigns against South Korean government entities through distributed denial-of-service assaults.

Lazarus Group has also used the SWIFT network to undertake assaults on global organizations such as Sony and banking institutions, as well as a large-scale ransomware attack that affected thousands of machines in countries such as Russia, India, Taiwan, and Ukraine. During the COVID-19 pandemic in late 2020, the criminal group used spear-phishing techniques to get into computers and stole proprietary COVID-19 research.

The group began 2022 with a $600 million heist on Ronin, the blockchain protocol associated with the renowned crypto game Axie Infinity. Lazarus Group has been linked to a new type of crypto hacking, promoting fake crypto applications under the brand BloxHolder to spread the AppleJeus malware and steal crypto funds. The group is responsible for more than 25 notable attacks. 

Atomic Wallet suffers loss under cyber criminals

The team behind Atomic Wallet, a non-custodial crypto wallet, announced early Saturday morning that some users had their wallets compromised and funds stolen. The number of incidents reportedly did not exceed 1% of “monthly active users.” The announcement followed many complaints on Reddit from users whose wallets had been emptied.

ZachXBT, a pseudonymous blockchain detective, estimated that approximately $35 million worth of crypto had been stolen, including bitcoin, ether, tether, dogecoin, Litecoin, BNB coin, polygon, and Tron-based USDT.

Elliptic wrote that the stolen crypto was transferred to a mixer called Sindbad.io. This mixer, which Elliptic believes is a successor to the previously sanctioned mixer Blender.io, has frequently been used to launder money from other hacks attributed to Lazarus, according to Elliptic, who noted that the utilization pattern is identical. According to the blog post, the company also discovered connections between the wallets containing the stolen funds from Atomic and some of the Lazarus breaches.

Non-custodial wallets, such as Atomic, allow users to retain their crypto autonomously, without relying on a centralized entity, which means that if users lose their wallet’s device or password, they can only recover funds using the seed phrase. Anyone with access to the seed phrase, on the other hand, can clone the wallet and steal the funds.

Three hours ago, Elliptic Investigations updated that Atomic Wallet hack funds have just been swapped for USDT and bridged to TRON.

It’s probable that the stolen crypto assets were mixed in wallets containing the proceeds of previous Lazarus Group attacks. This would be the first large crypto theft openly traced to Lazarus Group since the $100 million Horizon Bridge breach in June 2022. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decision.

文章来源于互联网:North Korean Hackers, Lazarus group, tied to the Atomic Wallet breach

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月12日 11:23
Next 2023年6月12日 12:06

Related articles

  • Is SEC Chairperson, Gary Gensler, resigning?

    TL;DR Breakdown Rumors have it that SEC’s chair Gary Gensler is set to resign due to the ongoing internal inquiry. The crypto community had reacted positively to the fake news of Gensler’s resignation. The crypto community is asking for general regulation change than only the removal of Gensler. Description On Sunday, a rumor arose in the crypto market about the likely resignation of US Securities and Exchange Commission (SEC) Chair Gary Gensler. According to reports from an anonymous official at the regulatory entity, the SEC Chair was poised to quit as a result of an internal agency inquiry.  Gary Gensler’s fake resignation news crush … Read more On Sunday, a rumor arose in the crypto market about the likely resignation of US Securities and Exchange Commission (SEC) Chair Gary Gensler. According to reports from an anonymous official at the regulatory entity, the SEC Chair was poised to quit as a result of an internal agency inquiry.  Gary Gensler’s fake resignation news crush the crypto community However, the SEC’s public relations (PR) team disputes rumors of Chairperson Gary Gensler’s resignation, putting…

    Article 2023年7月5日
  • US lawmakers question Apple’s policies on stifling blockchain innovation

    TL;DR Breakdown US lawmakers Bilirakis and Schakowsky have written to Apple to clarify App Store’s crypto-related app policy. The legislators wrote to CEO Tim Cook to voice their displeasure over the limitations placed on emerging technologies like blockchains and NFTs. The crypto industry is in support of the legislators calling out Big Tech. Description Apple faces a bipartisan investigation into the App Store’s regulations and procedures addressing applications connected to NFTs and the larger crypto industry. Gus Bilirakis, a Republican, and Jan Schakowsky, a Democrat, have written a letter to CEO Tim Cook requesting details on the restricted crypto policy of the App Store. Apple’s policies may be undermining … Read more Apple faces a bipartisan investigation into the App Store’s regulations and procedures addressing applications connected to NFTs and the larger crypto industry. Gus Bilirakis, a Republican, and Jan Schakowsky, a Democrat, have written a letter to CEO Tim Cook requesting details on the restricted crypto policy of the App Store. Apple’s policies may be undermining US technological leadership The two representatives who are also the chairman and ranking…

    Article 2023年7月29日
  • Curve Finance confirms the affected pools in the platform’s exploit

    TL;DR Breakdown Curve Finance has confirmed the list of affected pools following the recent hack that it suffered. Assessing the impact and strengthening security for the future. Description Curve Finance, a popular decentralized exchange (DEX), recently faced a significant security breach that affected multiple Ethereum pools and an Arbitrum-based liquidity pool. The incident occurred over the weekend, leading to the theft of millions of dollars. As the situation unfolded, blockchain security firm PeckShield updated the stolen amount to an alarming $52 million. Curve … Read more Curve Finance, a popular decentralized exchange (DEX), recently faced a significant security breach that affected multiple Ethereum pools and an Arbitrum-based liquidity pool. The incident occurred over the weekend, leading to the theft of millions of dollars. As the situation unfolded, blockchain security firm PeckShield updated the stolen amount to an alarming $52 million. Curve Finance’s DEX allows users to swap like-assets, such as Ethereum for Staked Ethereum or Tether’s USDT for Circle’s USDC. Curve Finance reveals updated information about the hack The platform serves as a valuable arbitrage tool for traders seeking to…

    Article 2023年8月1日
  • “The Next Crypto Gem” TV show premieres on September 7th in 56 countries

    TL;DR Breakdown The Next Crypto Gem, dubbed “the Shark Tank of crypto,” goes live on September 7th in 56 countries.  The show is produced by The Hourglass Collective, a Web3 incubator with an aim to bridge the gap between crypto and mainstream entertainment. Season 2 planning is underway as the show takes major turns in setting the ground for global crypto adoption. Description The world of crypto is coming live to you in a matter of hours. The Next Crypto Gem, a show many have dubbed “the Shark Tank of crypto,” premiers on September 7th in 56 countries. What can investors, enthusiasts, and critics expect? As per the production reports, The Next Crypto Gem draws its inspiration from … Read more The world of crypto is coming live to you in a matter of hours. The Next Crypto Gem, a show many have dubbed “the Shark Tank of crypto,” premiers on September 7th in 56 countries. What can investors, enthusiasts, and critics expect? As per the production reports, The Next Crypto Gem draws its inspiration from entrepreneurial TV shows such…

    Article 2023年9月7日
  • GitHub urges the European Union to reconsider its AI Act

    TL;DR Breakdown GitHub and a list of other tech firms have urged the European Union to reconsider its AI Act. The group underscores the importance of AI regulation. Description In a joint effort, GitHub, Hugging Face, Creative Commons, and other tech companies have penned an open letter appealing to European Union (EU) policymakers to revise certain aspects of the EU’s Artificial Intelligence Act. The letter expresses concerns that upcoming rules may inadvertently impede the development of open-source artificial intelligence (AI) models. GitHub joins other … Read more In a joint effort, GitHub, Hugging Face, Creative Commons, and other tech companies have penned an open letter appealing to European Union (EU) policymakers to revise certain aspects of the EU’s Artificial Intelligence Act. The letter expresses concerns that upcoming rules may inadvertently impede the development of open-source artificial intelligence (AI) models. GitHub joins other firms in an open letter to the EU The primary contention raised in the GitHub open letter is that treating upstream open-source projects as if they were commercial products or deployed AI systems could hinder the progress of…

    Article 2023年7月30日
TOP