North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

TL;DR Breakdown

  • North Korean APT group Konni exploited a newly disclosed WinRAR vulnerability (CVE-2023-38831) to launch its first-ever attack on the cryptocurrency industry, marking a significant shift in its target sectors.
  • The sophisticated malware used by Konni could adapt its tactics based on the system’s architecture, employing different User Account Control (UAC) bypass techniques to execute its payload.
  • Konni’s entry into targeting the cryptocurrency sector indicates a broader strategy by North Korean hackers, raising concerns about the industry’s preparedness against advanced and evolving cybersecurity threats.

Description

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector. A new vector of attack North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm … Read more

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector.

A new vector of attack

North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm Chuangyu 404 Lab.  This move represents a deviation from their targets, primarily in South Korea, and the first instance of an APT group leveraging this particular vulnerability for an attack. 

In a statement on Seeburg, the group used a malicious payload disguised as a wallet screenshot, specifically targeting the cryptocurrency sector. The payload was named “wallet_Screenshot_2023_09_06_Qbao_Network.zip,” hinting at Qbao Network, a smart cryptocurrency wallet service. This deviation from their usual targets suggests that Konni may be diversifying its attack vectors.

Technical insights and tactics

The vulnerability in question, CVE-2023-38831, allows for the execution of a malicious payload when the victim clicks a specially crafted HTML file within a compressed archive. Also, the payload then runs a series of commands to determine the system architecture and downloads additional payloads from a remote server.

The malware employed by Konni was sophisticated enough to detect the system’s architecture and adapt its tactics accordingly. It used different User Account Control (UAC) bypass techniques based on the system’s specifications, making it a highly adaptable threat.

Until now, North Korean attacks on the cryptocurrency industry were primarily attributed to the Lazarus Group. The entry of Konni into this space indicates a broader strategy by North Korean hackers to target cryptocurrency exchanges and financial platforms. 

This development is particularly concerning given recent incidents involving other cryptocurrency platforms like Stake and CoinEx. The attack also raises questions about the preparedness of the cryptocurrency industry to fend off sophisticated threats, especially those that exploit newly disclosed vulnerabilities.

The attack by Konni serves as a wake-up call for both the cybersecurity and cryptocurrency communities. With the exploitation of a new vulnerability and a shift in target industries, Konni has demonstrated the evolving nature of APT threats. Organizations, especially those in the cryptocurrency sector, need to be vigilant and proactive in updating their security measures to defend against these advanced and ever-changing threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年9月16日 01:10
Next 2023年9月16日 02:48

Related articles

  • BlackRock’s BTC ETF approval hangs in the balance with a 50-chance for greenlight

    TL;DR Breakdown Bloomberg senior ETF analyst Eric Balchunas gives BlackRock a 50-50 chance of getting its BTC ETF approved by American financial regulators. Balchunas’ prediction follows Bloomberg Intelligence senior litigation analyst Elliott Stein’s assessment that Grayscale has a 70% chance of winning its case against the SEC. Balchunas says that the SEC might view BlackRock’s ETF filing positively as a chance to “save face” following the recent crypto crackdown. Description According to Bloomberg senior ETF analyst Eric Balchunas, investment management giant BlackRock has a 50% probability of getting its spot Bitcoin Exchange Traded Fund (ETF) approved. The approval of BlackRock’s Bitcoin ETF could mark a groundbreaking moment for the cryptocurrency industry.  As the world’s largest asset management firm, BlackRock’s foray into the realm of digital … Read more According to Bloomberg senior ETF analyst Eric Balchunas, investment management giant BlackRock has a 50% probability of getting its spot Bitcoin Exchange Traded Fund (ETF) approved. The approval of BlackRock’s Bitcoin ETF could mark a groundbreaking moment for the cryptocurrency industry.  As the world’s largest asset management firm, BlackRock’s foray into the…

    Article 2023年6月30日
  • Namibia’s crypto assets bill becomes law, ushers in era of digital asset regulation

    TL;DR Breakdown Namibia has signed the Virtual Assets Act 2023 into law, marking a critical moment in cryptocurrency regulation. The Act aims to safeguard consumers and curb illegal activities like money laundering and terrorist financing. The Bank of Namibia stated that cryptocurrencies would not be considered legal tender, distinguishing digital assets from traditional money.   Description Namibia has embraced the world of cryptocurrencies by signing the groundbreaking Virtual Assets Act 2023 into law. The legislation marks a pivotal moment for the nation, laying down clear guidelines for regulating crypto exchanges within its borders. This move comes after the government initially banned cryptocurrency exchanges in 2017, only to reverse course in 2018, … Read more Namibia has embraced the world of cryptocurrencies by signing the groundbreaking Virtual Assets Act 2023 into law. The legislation marks a pivotal moment for the nation, laying down clear guidelines for regulating crypto exchanges within its borders. This move comes after the government initially banned cryptocurrency exchanges in 2017, only to reverse course in 2018, signaling a shift towards digital asset acceptance. The Namibian Ministry of…

    Article 2023年7月26日
  • Terra Classic’s  bid to combat spam

    TL;DR Breakdown This proposal revolves around increasing the minimum deposit requirement on the Terra Classic chain, which currently stands at one million Terra Luna Classic (LUNC), an equivalent of approximately $57.23. The rationale behind this proposal lies in the depreciation of both $LUNC and $USTC prices.  Description The Terra Classic community finds itself grappling with challenges and has put forth a proposal aimed at addressing some pressing issues within the Terra Classic chain. Specifically, this proposal revolves around increasing the minimum deposit requirement on the Terra Classic chain, which currently stands at one million Terra Luna Classic (LUNC), an equivalent of approximately … Read more The Terra Classic community finds itself grappling with challenges and has put forth a proposal aimed at addressing some pressing issues within the Terra Classic chain. Specifically, this proposal revolves around increasing the minimum deposit requirement on the Terra Classic chain, which currently stands at one million Terra Luna Classic (LUNC), an equivalent of approximately $57.23. This proposal, known as Parameter Change Proposal #11780, identifies a significant uptick in spam proposals on the blockchain as…

    Article 2023年9月12日
  • US government suspected of owning $2.46 billion in Bitcoin

    TL;DR Breakdown The US Government is suspected of controlling the fifth-largest Bitcoin wallet globally, with holdings equivalent to $2.46 billion. Investigations found a link between the hack’s seizure address and the wallet’s owner, with notable transfers of significant BTC amounts. In 2022, the US Department of Justice recovered about $3.55 billion in stolen Bitcoin from the said account. Description Recent findings suggest that the US Government might control the global fifth-largest Bitcoin (BTC) wallet, containing 94,643 BTC, equivalent to $2.46 billion. This revelation came from the esteemed cybersecurity firm, Peckshield. The wallet is believed to have direct ties to the 2016 Bitfinex hack. Investigations have unveiled a connection between the hack’s seizure address and … Read more Recent findings suggest that the US Government might control the global fifth-largest Bitcoin (BTC) wallet, containing 94,643 BTC, equivalent to $2.46 billion. This revelation came from the esteemed cybersecurity firm, Peckshield. The wallet is believed to have direct ties to the 2016 Bitfinex hack. Investigations have unveiled a connection between the hack’s seizure address and the wallet’s owner. Notably, a transfer was made…

    Article 2023年8月31日
  • Top game dapp Iskra to launch Clashmon during base mainnet onchain summer roll out

    TL;DR Breakdown Starting on August 27, the ClashMon Onchain Summer Event allows players to mint a Game NFT Mystery Box and reveal their own ClashMon Monster, ClashMon gear, and ClashMon Tokens. Iskra believes that onboarding the next generation of on-chain users will be driven by engaging games that demonstrate the actual value of digital ownership.  Description Base opened mainnet for everyone on August 9  with their on-chain Summer campaign, featuring over 50 leading brands to connect users with the best on-chain art, music, and games daily throughout August. Top-ranking game Dapp Iskra will be one of the gaming category’s features, releasing its latest Free to Play game, ClashMon: Ignition. The ClashMon … Read more Base opened mainnet for everyone on August 9  with their on-chain Summer campaign, featuring over 50 leading brands to connect users with the best on-chain art, music, and games daily throughout August. Top-ranking game Dapp Iskra will be one of the gaming category’s features, releasing its latest Free to Play game, ClashMon: Ignition. The ClashMon Collectible Battle RPG offers its first minting opportunity on Base Mainnet…

    Article 2023年8月25日
TOP