North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

TL;DR Breakdown

  • North Korean APT group Konni exploited a newly disclosed WinRAR vulnerability (CVE-2023-38831) to launch its first-ever attack on the cryptocurrency industry, marking a significant shift in its target sectors.
  • The sophisticated malware used by Konni could adapt its tactics based on the system’s architecture, employing different User Account Control (UAC) bypass techniques to execute its payload.
  • Konni’s entry into targeting the cryptocurrency sector indicates a broader strategy by North Korean hackers, raising concerns about the industry’s preparedness against advanced and evolving cybersecurity threats.

Description

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector. A new vector of attack North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm … Read more

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector.

A new vector of attack

North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm Chuangyu 404 Lab.  This move represents a deviation from their targets, primarily in South Korea, and the first instance of an APT group leveraging this particular vulnerability for an attack. 

In a statement on Seeburg, the group used a malicious payload disguised as a wallet screenshot, specifically targeting the cryptocurrency sector. The payload was named “wallet_Screenshot_2023_09_06_Qbao_Network.zip,” hinting at Qbao Network, a smart cryptocurrency wallet service. This deviation from their usual targets suggests that Konni may be diversifying its attack vectors.

Technical insights and tactics

The vulnerability in question, CVE-2023-38831, allows for the execution of a malicious payload when the victim clicks a specially crafted HTML file within a compressed archive. Also, the payload then runs a series of commands to determine the system architecture and downloads additional payloads from a remote server.

The malware employed by Konni was sophisticated enough to detect the system’s architecture and adapt its tactics accordingly. It used different User Account Control (UAC) bypass techniques based on the system’s specifications, making it a highly adaptable threat.

Until now, North Korean attacks on the cryptocurrency industry were primarily attributed to the Lazarus Group. The entry of Konni into this space indicates a broader strategy by North Korean hackers to target cryptocurrency exchanges and financial platforms. 

This development is particularly concerning given recent incidents involving other cryptocurrency platforms like Stake and CoinEx. The attack also raises questions about the preparedness of the cryptocurrency industry to fend off sophisticated threats, especially those that exploit newly disclosed vulnerabilities.

The attack by Konni serves as a wake-up call for both the cybersecurity and cryptocurrency communities. With the exploitation of a new vulnerability and a shift in target industries, Konni has demonstrated the evolving nature of APT threats. Organizations, especially those in the cryptocurrency sector, need to be vigilant and proactive in updating their security measures to defend against these advanced and ever-changing threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年9月16日 01:10
Next 2023年9月16日 02:48

Related articles

  • Bankrupt FTX exchange files lawsuit to recover $157.3 million from former Hong Kong affiliates

    TL;DR Breakdown FTX sues former Salameda employees to recover $157.3 million withdrawn before bankruptcy. Defendants allegedly used insider connections to prioritize their withdrawals. Lawsuit occurs as former FTX CEO Sam Bankman-Fried awaits trial in jail. Description Bankrupt cryptocurrency exchange FTX has initiated legal action against former employees of Salameda, a Hong Kong-based entity once affiliated with FTX.  As stated in a recent court filing, the lawsuit aims to recover approximately $157.3 million. The defendants, including Michael Burgess, Matthew Burgess, Lesley Burgess, Kevin Nguyen, and Darren Wong, allegedly exploited their connections to … Read more Bankrupt cryptocurrency exchange FTX has initiated legal action against former employees of Salameda, a Hong Kong-based entity once affiliated with FTX.  As stated in a recent court filing, the lawsuit aims to recover approximately $157.3 million. The defendants, including Michael Burgess, Matthew Burgess, Lesley Burgess, Kevin Nguyen, and Darren Wong, allegedly exploited their connections to FTX personnel.  Consequently, they managed to fraudulently withdraw assets in the days leading up to FTX’s bankruptcy filing on November 11, 2022. The court documents reveal that the defendants benefited from…

    Article 2023年9月24日
  • Diverse perspectives in BRICS over expansion plans

    TL;DR Breakdown The upcoming BRICS summit will focus on the potential expansion of the alliance, with China pushing for growth and other members like India and Brazil showing reluctance. The discussions on enlargement reflect BRICS’ growing global influence, and the decision could position the alliance as a counterweight to the U.S. and the EU. The diverse perspectives within BRICS on expansion may either foster unity or sow discord, marking a defining moment in the alliance’s history. Description As the international scene continues to evolve, the robust alliance known as BRICS (Brazil, Russia, India, China, and South Africa) finds itself at a crossroads. Set to convene this month in Johannesburg, the upcoming summit has been marked by an overarching question: Should BRICS expand? With China pushing for rapid growth and other member nations … Read more As the international scene continues to evolve, the robust alliance known as BRICS (Brazil, Russia, India, China, and South Africa) finds itself at a crossroads. Set to convene this month in Johannesburg, the upcoming summit has been marked by an overarching question: Should BRICS expand?…

    Article 2023年8月5日
  • Ripple vs. SEC trial dates revealed

    TL;DR Breakdown Ripple Labs and the Securities and Exchange Commission (SEC) have reportedly submitted a list of dates indicating their availability and unavailability for the upcoming trial, scheduled for the second quarter of next year.  Ripple’s CEO Brad Garlinghouse and co-founder Chris Larsen informed Judge Torres that the timeframe from April 1 to April 14 would be inconvenient for their participation. The SEC also submitted a response indicating its willingness to participate in April, May, and June, but excluded specific dates from its list, such as April 15-19, May 1-7, and May 27-31.  Description In the ongoing legal battle between Ripple Labs and the Securities and Exchange Commission (SEC), both parties have reportedly submitted a list of dates indicating their availability and unavailability for the upcoming trial, scheduled for the second quarter of next year. This development comes as part of the protracted legal proceedings surrounding the classification of … Read more In the ongoing legal battle between Ripple Labs and the Securities and Exchange Commission (SEC), both parties have reportedly submitted a list of dates indicating their availability and…

    Article 2023年8月24日
  • Robert Kiyosaki calls WSJ ‘numb nuts’ for claiming the US economy is strong

    TL;DR Breakdown Robert Kiyosaki, the Rich Dad Poor Dad author, disapproves of the Wall Street Journal(WSJ), claiming that the U.S. economy is strong. He called WSJ ‘numb nuts’ for not seeing that the United States is broke since the stock market was only going up due to the raised debt ceiling. Kiyosaki reassures his support for gold, silver and bitcoin. Description Robert Kiyosaki, the Rich Dad Poor Dad author, has explained in a Twitter post that he disapproves of Wall Street Journal(WSJ) claims that the U.S. economy was strong. He explained that the stock market is only up due to Joe Biden, the U.S. president, raising the debt ceiling. Kiyosaki continued, calling them ‘numb nuts’ for … Read more Robert Kiyosaki, the Rich Dad Poor Dad author, has explained in a Twitter post that he disapproves of Wall Street Journal(WSJ) claims that the U.S. economy was strong. He explained that the stock market is only up due to Joe Biden, the U.S. president, raising the debt ceiling. Kiyosaki continued, calling them ‘numb nuts’ for not seeing that the United States…

    Article 2023年7月31日
  • AI Camera Catches Hundreds in UK Texting While Driving

    TL;DR Breakdown The UK deploys AI cameras on roads trained by Tech firm Ascensus to spot violations through clear images. AI camera checks for seatbelt and phone violations and flags offenders to deter risky behaviors on UK roads. UK success with AI camera prompts global interest and transforms road safety efforts and shapes responsible driving. Description In a pioneering effort to enhance road safety, the United Kingdom has introduced an artificial intelligence (AI) camera system on a major highway, which has identified approximately 300 individuals engaging in texting while driving. This initiative is part of a wider strategy by law enforcement agencies to mitigate traffic accidents. Devon and Cornwall Police’s road … Read more In a pioneering effort to enhance road safety, the United Kingdom has introduced an artificial intelligence (AI) camera system on a major highway, which has identified approximately 300 individuals engaging in texting while driving. This initiative is part of a wider strategy by law enforcement agencies to mitigate traffic accidents. Devon and Cornwall Police’s road safety head, Adrian Leisk, stressed that deploying this technology sends a…

    Article 2023年8月23日
TOP