North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

TL;DR Breakdown

  • North Korean APT group Konni exploited a newly disclosed WinRAR vulnerability (CVE-2023-38831) to launch its first-ever attack on the cryptocurrency industry, marking a significant shift in its target sectors.
  • The sophisticated malware used by Konni could adapt its tactics based on the system’s architecture, employing different User Account Control (UAC) bypass techniques to execute its payload.
  • Konni’s entry into targeting the cryptocurrency sector indicates a broader strategy by North Korean hackers, raising concerns about the industry’s preparedness against advanced and evolving cybersecurity threats.

Description

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector. A new vector of attack North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm … Read more

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector.

A new vector of attack

North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm Chuangyu 404 Lab.  This move represents a deviation from their targets, primarily in South Korea, and the first instance of an APT group leveraging this particular vulnerability for an attack. 

In a statement on Seeburg, the group used a malicious payload disguised as a wallet screenshot, specifically targeting the cryptocurrency sector. The payload was named “wallet_Screenshot_2023_09_06_Qbao_Network.zip,” hinting at Qbao Network, a smart cryptocurrency wallet service. This deviation from their usual targets suggests that Konni may be diversifying its attack vectors.

Technical insights and tactics

The vulnerability in question, CVE-2023-38831, allows for the execution of a malicious payload when the victim clicks a specially crafted HTML file within a compressed archive. Also, the payload then runs a series of commands to determine the system architecture and downloads additional payloads from a remote server.

The malware employed by Konni was sophisticated enough to detect the system’s architecture and adapt its tactics accordingly. It used different User Account Control (UAC) bypass techniques based on the system’s specifications, making it a highly adaptable threat.

Until now, North Korean attacks on the cryptocurrency industry were primarily attributed to the Lazarus Group. The entry of Konni into this space indicates a broader strategy by North Korean hackers to target cryptocurrency exchanges and financial platforms. 

This development is particularly concerning given recent incidents involving other cryptocurrency platforms like Stake and CoinEx. The attack also raises questions about the preparedness of the cryptocurrency industry to fend off sophisticated threats, especially those that exploit newly disclosed vulnerabilities.

The attack by Konni serves as a wake-up call for both the cybersecurity and cryptocurrency communities. With the exploitation of a new vulnerability and a shift in target industries, Konni has demonstrated the evolving nature of APT threats. Organizations, especially those in the cryptocurrency sector, need to be vigilant and proactive in updating their security measures to defend against these advanced and ever-changing threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年9月16日 01:10
Next 2023年9月16日 02:48

Related articles

  • CoinEX restarts operations with a new wallet system

    TL;DR Breakdown CoinEX has announced the restart of its services using a new wallet system after its previous hack. Restarting services on the platform and the way forward. Description Cryptocurrency exchange CoinEx is gearing up to resume deposit and withdrawal services for its users following a devastating $70 million hack, which occurred due to compromised hot wallet private keys. The exchange had previously outlined its commitment to developing a new wallet system that would support its extensive range of 211 blockchains and 737 tokens, … Read more Cryptocurrency exchange CoinEx is gearing up to resume deposit and withdrawal services for its users following a devastating $70 million hack, which occurred due to compromised hot wallet private keys. The exchange had previously outlined its commitment to developing a new wallet system that would support its extensive range of 211 blockchains and 737 tokens, all of which were affected by the hacking incident. CoinEX enables deposits and withdrawals In its latest statement, CoinEx announced the resumption of deposit and withdrawal services for major cryptocurrencies, including Bitcoin (BTC), Ethereum (ETH), Tether (USDT), USD…

    Article 2023年9月21日
  • Binance CEO Responds to Misleading Data on Crypto Outflows Amid SEC Lawsuits

    TL;DR Breakdown Binance CEO CZ refutes reported outflows as inaccurate and clarifies that crypto price drops should not be classified as outflows. He emphasizes the need to consider inflows and market dynamics. The market reacts positively to CZ’s clarification, with Binance’s native cryptocurrency, BNB, experiencing a 0.83% gain in price shortly after the announcement. Binance, the world’s largest cryptocurrency exchange, has faced significant scrutiny recently due to lawsuits filed by the U.S. Securities and Exchange Commission (SEC). Reports of outflows from the exchange have drawn attention, but Binance CEO Changpeng Zhao, known as CZ, has taken to Twitter to address the issue. He refutes the reported outflows as inaccurate and highlights the misinterpretation of Asset Under Management (AUM) changes by certain third-party analysis firms. CZ emphasizes the need to consider market fluctuations and overall dynamics when assessing Binance’s asset movements. Contents hide 1 CZ Clarifies Misleading Data on Crypto Outflows 2 Understanding the Impact of Market Fluctuations on AUM 3 Binance’s Response and Market Reaction 4 Conclusion CZ Clarifies Misleading Data on Crypto Outflows Binance CEO CZ has responded to…

    Article 2023年6月13日
  • UAE is becoming the leading destination for Bitcoin miners: Reports

    TL;DR Breakdown The United Arab Emirates (UAE)has established itself as a pro-Web3 and crypto-friendly environment with over 30 free trade zones and a growing contribution to the Bitcoin mining hash rate. Currently, the UAE’s combined Bitcoin mining capacity is estimated to be around 400 MW, accounting for approximately 4% of Bitcoin’s global hash rate. The country experiences significant fluctuations in electricity demand between the hottest and coolest months, resulting in a considerable loss of generated electricity. Description The United Arab Emirates (UAE) is quickly emerging as a leading destination for Bitcoin mining in the Middle East. With over 30 free trade zones and a growing contribution to the Bitcoin mining hash rate, the country has established itself as a pro-Web3 and crypto-friendly environment. In May, the country’s foray into Bitcoin mining began … Read more The United Arab Emirates (UAE) is quickly emerging as a leading destination for Bitcoin mining in the Middle East. With over 30 free trade zones and a growing contribution to the Bitcoin mining hash rate, the country has established itself as a pro-Web3 and crypto-friendly…

    Article 2023年7月8日
  • Floki Inu Price Prediction 2023-2032: Can FLOKI Surpass Previous ATH?

    Description Contents hide 1 Floki Inu Price Prediction 2023-2032 2 How Much is Floki Inu Worth? 3 Floki Inu price analysis: FLOKI maintains bullish trend at $0.00002265 4 Floki Inu price analysis for 1-hour: Recent updates 5 Floki Inu 1-day price analysis: FLOKI moves upwards to $0.00002265 5.1 What to Expect from the Floki Inu Price … Read more Contents hide 1 Floki Inu Price Prediction 2023-2032 2 How Much is Floki Inu Worth? 3 Floki Inu price analysis: FLOKI maintains bullish trend at $0.00002265 4 Floki Inu price analysis for 1-hour: Recent updates 5 Floki Inu 1-day price analysis: FLOKI moves upwards to $0.00002265 5.1 What to Expect from the Floki Inu Price Analysis 6 Floki Inu Price Predictions 2023 – 2032 6.1 Price Predictions by Cryptopolitan 6.1.1 Floki Inu Price Prediction 2023 6.1.2 Floki Inu Price Prediction 2024 6.1.3 Floki Inu Price Prediction 2025 6.1.4 Floki Inu Price Prediction 2026 6.1.5 Floki Inu Price Prediction 2027 6.1.6 Floki Inu Price Prediction 2028 6.1.7 Floki Inu Price Prediction 2029 6.1.8 Floki Inu Price Prediction 2030 6.1.9 Floki Inu Price…

    Article 2023年6月20日
  • House Speaker McCarthy calls for President Biden’s bank statements amid impeachment inquiry preparations

    TL;DR Breakdown McCarthy demands Biden’s bank statements amid impeachment inquiry preparations. The inquiry could empower Congress to obtain resisted information and lead to impeachment articles. The inquiry’s start could be delayed to October, pushing a final impeachment vote to January. Description House Speaker Kevin McCarthy has called on President Biden to release his bank statements to dispel allegations of benefiting from his family’s foreign business dealings. This demand comes as Republicans prepare to launch an impeachment inquiry as early as next month. McCarthy asserts that sufficient evidence suggests that the Biden family needs to demonstrate that … Read more House Speaker Kevin McCarthy has called on President Biden to release his bank statements to dispel allegations of benefiting from his family’s foreign business dealings. This demand comes as Republicans prepare to launch an impeachment inquiry as early as next month. McCarthy asserts that sufficient evidence suggests that the Biden family needs to demonstrate that there was no pay-to-play scheme involved in their foreign business transactions. The call for transparency is rooted in a controversial WhatsApp message dated July 30, 2017,…

    Article 2023年8月9日
TOP