North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

TL;DR Breakdown

  • North Korean APT group Konni exploited a newly disclosed WinRAR vulnerability (CVE-2023-38831) to launch its first-ever attack on the cryptocurrency industry, marking a significant shift in its target sectors.
  • The sophisticated malware used by Konni could adapt its tactics based on the system’s architecture, employing different User Account Control (UAC) bypass techniques to execute its payload.
  • Konni’s entry into targeting the cryptocurrency sector indicates a broader strategy by North Korean hackers, raising concerns about the industry’s preparedness against advanced and evolving cybersecurity threats.

Description

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector. A new vector of attack North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm … Read more

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector.

A new vector of attack

North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm Chuangyu 404 Lab.  This move represents a deviation from their targets, primarily in South Korea, and the first instance of an APT group leveraging this particular vulnerability for an attack. 

In a statement on Seeburg, the group used a malicious payload disguised as a wallet screenshot, specifically targeting the cryptocurrency sector. The payload was named “wallet_Screenshot_2023_09_06_Qbao_Network.zip,” hinting at Qbao Network, a smart cryptocurrency wallet service. This deviation from their usual targets suggests that Konni may be diversifying its attack vectors.

Technical insights and tactics

The vulnerability in question, CVE-2023-38831, allows for the execution of a malicious payload when the victim clicks a specially crafted HTML file within a compressed archive. Also, the payload then runs a series of commands to determine the system architecture and downloads additional payloads from a remote server.

The malware employed by Konni was sophisticated enough to detect the system’s architecture and adapt its tactics accordingly. It used different User Account Control (UAC) bypass techniques based on the system’s specifications, making it a highly adaptable threat.

Until now, North Korean attacks on the cryptocurrency industry were primarily attributed to the Lazarus Group. The entry of Konni into this space indicates a broader strategy by North Korean hackers to target cryptocurrency exchanges and financial platforms. 

This development is particularly concerning given recent incidents involving other cryptocurrency platforms like Stake and CoinEx. The attack also raises questions about the preparedness of the cryptocurrency industry to fend off sophisticated threats, especially those that exploit newly disclosed vulnerabilities.

The attack by Konni serves as a wake-up call for both the cybersecurity and cryptocurrency communities. With the exploitation of a new vulnerability and a shift in target industries, Konni has demonstrated the evolving nature of APT threats. Organizations, especially those in the cryptocurrency sector, need to be vigilant and proactive in updating their security measures to defend against these advanced and ever-changing threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年9月16日 01:10
Next 2023年9月16日 02:48

Related articles

  • Expert: BRICS expansion accelerates de-dollarization

    TL;DR Breakdown BRICS, comprising Brazil, Russia, India, China, and South Africa, is on the path of expansion. Expansion might promote the use of national currencies over the US dollar, leading to rapid de-dollarization. Sun Qi from Shanghai Academy predicts more national currency transactions as the bloc grows. Description The ever-evolving geopolitical landscape is witnessing a dramatic shift. The powerhouse that is the BRICS economic bloc, comprising Brazil, Russia, India, China, and South Africa, is expanding. As this behemoth grows, an inevitable consequence looms large on the horizon: the rapid acceleration of de-dollarization. Leading voices in the world of finance, especially from China, highlight … Read more The ever-evolving geopolitical landscape is witnessing a dramatic shift. The powerhouse that is the BRICS economic bloc, comprising Brazil, Russia, India, China, and South Africa, is expanding. As this behemoth grows, an inevitable consequence looms large on the horizon: the rapid acceleration of de-dollarization. Leading voices in the world of finance, especially from China, highlight how the increasing membership of BRICS can reshape the global economic order. Notably, the ascendance of national currencies over…

    Article 2023年8月21日
  • South Korea ushers in banking revolution, inviting new entrants for the first time after 30 years

    TL;DR Breakdown The South Korean government is allowing new entrants into the banking sector for the first time in 30 years to increase competition and address criticism over large employee bonuses. Measures include permitting more online banks, issuing commercial banking licenses to existing firms, and easing loan-to-deposit rules for foreign banks’ local branches. Despite concerns that these actions may not sufficiently stimulate competition, this move signifies a significant shift in South Korea’s banking industry landscape. Description South Korea, one of the world’s most vibrant economies, is witnessing an unprecedented shift in its banking industry. This comes as the government, to stimulate competition, is opening doors for new entrants into the banking sector for the first time in three decades. This move follows criticism of large bonuses paid to banking employees while … Read more South Korea, one of the world’s most vibrant economies, is witnessing an unprecedented shift in its banking industry. This comes as the government, to stimulate competition, is opening doors for new entrants into the banking sector for the first time in three decades. This move follows…

    Article 2023年7月7日
  • Internet Computer’s DFINITY announces $1 million grant for developers in Lugano in new partnership

    Description DFINITY Foundation, the not-for-profit organisation behind the development of Internet Computer blockchain, has entered a partnership with the municipality of Lugano, Switzerland, in line with the city’s plans to encourage blockchain development and ultimately become a regional crypto hub.  The Foundation is also launching a $1 million grant fund to encourage Lugano-based startups and developers. … Read more DFINITY Foundation, the not-for-profit organisation behind the development of Internet Computer blockchain, has entered a partnership with the municipality of Lugano, Switzerland, in line with the city’s plans to encourage blockchain development and ultimately become a regional crypto hub.  The Foundation is also launching a $1 million grant fund to encourage Lugano-based startups and developers. Per the announcement, the grant will be issued to developers leveraging the unique capabilities of the Internet Computer to build services that serve the global community. I am delighted to announce that the DFINITY Foundation has partnered with the Municipality of Lugano to award grants to Lugano-based blockchain companies. We are proud to support our local developer community, and this partnership is a major step forward…

    Article 2023年9月8日
  • Hooked Protocol price analysis: Price slumps to $1.40 as bears reactivate the downtrend

    TL;DR Breakdown The Hooked Protocol price analysis shows the price is going down once again. HOOK values has lowered to the $1.40 level. Support is for HOOK/USD is present at $1.29. Today, the Hooked Protocol price analysis indicates a bearish trend, with increased selling activity observed throughout the day. The price subsequently dropped to $1.40 as the bears regained their dominance. Despite a brief pause when the bulls attempted a comeback, the bears continue to dominate the price charts. Over the past 4 hours, the price has experienced a decline, aligning with the overall bearish trend observed. HOOK/USD 1-day price chart: Stepping down to $1.40, the price experiences a renewed downturn Based on the 1-day Hooked Protocol price analysis, a prominent bearish trend is evident as the price experienced a significant decline throughout the day. It has now reached the $1.40 level, primarily due to continuous corrections. Despite occasional bullish periods in the past week, the bears have managed to retain their dominance. The moving average (MA) value remains above the current price but below the SMA 50 curve, currently…

    Article 2023年5月25日
  • Corporate depositors push US banks for higher interest rates

    TL;DR Breakdown Corporate depositors are pushing US banks for higher interest rates, putting pressure on banks’ profit margins. US banks, having benefited from raising loan rates faster than savings interest rates, are now facing challenges as clients shift funds to higher-yielding accounts. Banks such as Bank of America, PNC, and BNY Mellon have reported drops in net interest income. Description The dynamics of the banking sector are undergoing a seismic shift as corporate depositors urge US banks to offer higher interest rates. This move is causing ripples of concern for the profitability of these financial institutions and underscores the growing challenges they face in generating revenue amidst tightening monetary policy. Corporate Demand Squeezes US Bank … Read more The dynamics of the banking sector are undergoing a seismic shift as corporate depositors urge US banks to offer higher interest rates. This move is causing ripples of concern for the profitability of these financial institutions and underscores the growing challenges they face in generating revenue amidst tightening monetary policy. Corporate Demand Squeezes US Bank Margins In the wake of aggressive rate…

    Article 2023年7月20日
TOP