North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

TL;DR Breakdown

  • North Korean APT group Konni exploited a newly disclosed WinRAR vulnerability (CVE-2023-38831) to launch its first-ever attack on the cryptocurrency industry, marking a significant shift in its target sectors.
  • The sophisticated malware used by Konni could adapt its tactics based on the system’s architecture, employing different User Account Control (UAC) bypass techniques to execute its payload.
  • Konni’s entry into targeting the cryptocurrency sector indicates a broader strategy by North Korean hackers, raising concerns about the industry’s preparedness against advanced and evolving cybersecurity threats.

Description

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector. A new vector of attack North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm … Read more

North Korean APT (Advanced Persistent Threat) group Konni exploits a recently disclosed WinRAR vulnerability to launch its first attack on the cryptocurrency sector.

A new vector of attack

North Korean APT group Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry, according to a Chinese security firm Chuangyu 404 Lab.  This move represents a deviation from their targets, primarily in South Korea, and the first instance of an APT group leveraging this particular vulnerability for an attack. 

In a statement on Seeburg, the group used a malicious payload disguised as a wallet screenshot, specifically targeting the cryptocurrency sector. The payload was named “wallet_Screenshot_2023_09_06_Qbao_Network.zip,” hinting at Qbao Network, a smart cryptocurrency wallet service. This deviation from their usual targets suggests that Konni may be diversifying its attack vectors.

Technical insights and tactics

The vulnerability in question, CVE-2023-38831, allows for the execution of a malicious payload when the victim clicks a specially crafted HTML file within a compressed archive. Also, the payload then runs a series of commands to determine the system architecture and downloads additional payloads from a remote server.

The malware employed by Konni was sophisticated enough to detect the system’s architecture and adapt its tactics accordingly. It used different User Account Control (UAC) bypass techniques based on the system’s specifications, making it a highly adaptable threat.

Until now, North Korean attacks on the cryptocurrency industry were primarily attributed to the Lazarus Group. The entry of Konni into this space indicates a broader strategy by North Korean hackers to target cryptocurrency exchanges and financial platforms. 

This development is particularly concerning given recent incidents involving other cryptocurrency platforms like Stake and CoinEx. The attack also raises questions about the preparedness of the cryptocurrency industry to fend off sophisticated threats, especially those that exploit newly disclosed vulnerabilities.

The attack by Konni serves as a wake-up call for both the cybersecurity and cryptocurrency communities. With the exploitation of a new vulnerability and a shift in target industries, Konni has demonstrated the evolving nature of APT threats. Organizations, especially those in the cryptocurrency sector, need to be vigilant and proactive in updating their security measures to defend against these advanced and ever-changing threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:North Korean APT group Konni targets the cryptocurrency industry using WinRAR vulnerability

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年9月16日 01:10
Next 2023年9月16日 02:48

Related articles

  • WazirX Reveals Ties with Binance and Raises Concerns Over WRX Token 

    TL;DR Breakdown WazirX revealed that Binance controls the WRX token and conducted the initial exchange offering (IEO), keeping the proceeds at nearly $2 million. Binance has failed to conduct quarterly burns for the past five quarters, raising concerns about its commitment to the WRX token. Indian cryptocurrency exchange WazirX recently provided additional clarity regarding its relationship with the world’s leading crypto exchange, Binance. In a blog post, WazirX disclosed that Binance controls the WRX token, shedding light on the initial exchange offering (IEO) and the subsequent management of the token. This revelation has raised concerns, particularly as Binance has failed to conduct quarterly burns for the past five quarters. In this article, we delve deeper into the details of WazirX’s ties with Binance, the concerns raised, and the potential implications for the WRX token and its users. Binance’s Control Over WRX Token WazirX confirmed that Binance conducted the WRX token IEO, retaining all the proceeds from the sale, which amounted to nearly $2 million. Currently, Binance holds a significant amount of WRX tokens, with a total of 580.78 million locked…

    Article 2023年5月19日
  • Biden’s secret move to outsmart China and mend relations

    TL;DR Breakdown A Chinese hacking operation breached U.S. government email systems during Antony Blinken’s visit to Beijing, potentially gaining insights into U.S. strategic intentions. Despite the cyber intrusion, the Biden administration is using this incident to mend relations with China, maintaining diplomacy and focus on long-term relations. No public response with specific reprisals against China was given by the U.S., indicating a delicate handling of the situation. Description Behind the scenes of international diplomacy, unseen events shape the trajectory of global relationships. One such event is the recent maneuver by the Biden administration to pivot from an alarming cybersecurity breach. Despite a Chinese hacking operation that infiltrated U.S. government email systems, the administration’s focus is on mend relations with China, harnessing adversity for … Read more Behind the scenes of international diplomacy, unseen events shape the trajectory of global relationships. One such event is the recent maneuver by the Biden administration to pivot from an alarming cybersecurity breach. Despite a Chinese hacking operation that infiltrated U.S. government email systems, the administration’s focus is on mend relations with China, harnessing adversity…

    Article 2023年7月15日
  • Deputy governor of India’s reserve bank raises concerns over stablecoins’ impact on policy sovereignty

    TL;DR Breakdown RBI Deputy Governor expresses concerns over stablecoins, citing potential risks to policy sovereignty and dollarization. Sankar suggests CBDCs as stable solutions for each country, enabling interaction and transactions between different CBDCs. He highlights the need to address inefficiencies in the global payment system, particularly in cross-border remittances, and urges banks to reevaluate their remittance structures. Description Deputy Governor of the Reserve Bank of India (RBI), T Rabi Sankar, has expressed concerns about stablecoins, warning that they pose an existential threat to policy sovereignty. Speaking at an event organized by the Indian Banks’ Association, Sankar emphasized that stablecoins, while beneficial to certain economies, can potentially replace the local currency and transfer profits … Read more Deputy Governor of the Reserve Bank of India (RBI), T Rabi Sankar, has expressed concerns about stablecoins, warning that they pose an existential threat to policy sovereignty. Speaking at an event organized by the Indian Banks’ Association, Sankar emphasized that stablecoins, while beneficial to certain economies, can potentially replace the local currency and transfer profits from the government to private issuers. Implications for policy…

    Article 2023年7月13日
  • Binance.US lists Ripple’s XRP token following court ruling

    TL;DR Breakdown Binance.US relists Ripple’s XRP token after a court ruling on its non-security status. Other major exchanges, including Coinbase and Gemini, also announce the re-listing of XRP. The court ruling brings hope to XRP investors and sparks cryptocurrency regulations and securities classification discussions. Description Binance.US, the U.S. subsidiary of the world’s largest crypto exchange by volume, Binance, has announced the relisting of Ripple‘s XRP token in a significant development for the cryptocurrency market. Also, this decision comes on the heels of a recent U.S. federal court ruling that deemed the secondary sales of XRP on exchanges as non-securities. Binance.US … Read more Binance.US, the U.S. subsidiary of the world’s largest crypto exchange by volume, Binance, has announced the relisting of Ripple‘s XRP token in a significant development for the cryptocurrency market. Also, this decision comes on the heels of a recent U.S. federal court ruling that deemed the secondary sales of XRP on exchanges as non-securities. Binance.US joined other major crypto exchanges, such as Coinbase, Kraken, and Bitstamp, which have already re-listed XRP on their platforms. With the relisting…

    Article 2023年7月15日
  • Bitfinex reveals strategic Bitcoin holdings amid market upswing

    TL;DR Breakdown Bitfinex has disclosed that it holds Bitcoin as a long-term investment, although specific figures are not revealed. Paolo Ardoino, Bitfinex’s CTO, advocates for crypto exchanges to reinvest profits into Bitcoin, highlighting Bitfinex’s commitment. Tether plans to allocate up to 15% of its profits to Bitcoin, shifting its reserves away from U.S. government debt. Description In a recent revelation, Bitfinex has disclosed its strategic commitment to Bitcoin (BTC). Historically, the platform has retained some of its trading fee earnings in Bitcoin. This move showcases Bitfinex’s unwavering faith in the pioneering cryptocurrency. However, the exact figures remain undisclosed. Bitfinex’s Chief Technical Officer, Paolo Ardoino, took to Twitter on Sunday. He emphasized … Read more In a recent revelation, Bitfinex has disclosed its strategic commitment to Bitcoin (BTC). Historically, the platform has retained some of its trading fee earnings in Bitcoin. This move showcases Bitfinex’s unwavering faith in the pioneering cryptocurrency. However, the exact figures remain undisclosed. Bitfinex’s Chief Technical Officer, Paolo Ardoino, took to Twitter on Sunday. He emphasized that crypto exchanges, which have reaped significant benefits from Bitcoin, should…

    Article 2023年9月5日
TOP