Debridge Finance, Kuzey Kore Hacking Sendikası Lazarus Group'un Protokol Ekibine Saldırdığından Şüpheleniyor

Debridge Finance, Kuzey Kore Hacking Sendikası Lazarus Group'un Protokol Ekibine Saldırdığından Şüpheleniyor

According to the co-founder of Debridge Finance, Alex Smirnov, the infamous North Korean hacking syndicate Lazarus Group subjected Debridge to an attempted cyberattack. Smirnov has warned Web3 teams that the campaign is likely widespread.

Lazarus Group Suspected of Attacking Debridge Finance Team Members With a Malicious Group Email

There’s been a great number of attacks against decentralized finance (tanım) protocols like cross-chain bridges in 2022. While most of the hackers are unknown, it’s been suspected that the North Korean hacking collective Lazarus Group has been behind a number of defi exploits.

In mid-April 2022, Federal Soruşturma Bürosu (FBI), the U.S. Hazine Müsteşarlığı, and the Cybersecurity and Infrastructure Security Agency (CISA) söz konusu Lazarus Group was a threat to the crypto industry and participants. A week after the FBI’s warning, the U.S. Treasury Department’s Office of Foreign Asset Control (OFAC) katma three Ethereum-based addresses to the Specially Designated Nationals And Blocked Persons List (SDN).

OFAC alleged that the group of Ethereum addresses are maintained by members of the cybercrime syndicate Lazarus Group. bunlara ek olarak, OFAC connected the flagged ethereum addresses with the Ronin bridge exploit (the $620M Axie Infinity hack) to the group of North Korean hackers. Cuma gününde, Alex Smirnov, the co-founder of Debridge Finance, alerted the crypto and Web3 community about Lazarus Group allegedly attempting to attack the project.

“[Debridge Finance] has been the subject of an attempted cyberattack, apparently by the Lazarus group. PSA for all teams in Web3, this campaign is likely widespread,” Smirnov stressed in his tweet. “The attack vector was via email, with several of our team receiving a PDF file named “New Salary Adjustments” from an email address spoofing mine. We have strict internal security policies and continuously work on improving them as well as educating the team about possible attack vectors.” Smirnov continued, adding:

Most of the team members immediately reported the suspicious email, but one colleague downloaded and opened the file. This made us investigate the attack vector to understand how exactly it was supposed to work and what the consequences would be.

Smirnov insisted that the attack would not infect macOS users but when Windows users open the password-protected pdf, they are asked to use the system password. “The attack vector is as follows: user opens [en] link from email -> downloads & opens archive -> tries to open PDF, but PDF asks for a password -> user opens password.txt.lnk and infects the whole system,” Smirnov tweetlendi.

Smirnov said that according to this Twitter thread the files contained in the attack against the Debridge Finance team were the same names and “attributed to Lazarus Group.” The Debridge Finance executive sonuçlandı:

Never open email attachments without verifying the sender’s full email address, and have an internal protocol for how your team shares attachments. Please stay SAFU and share this thread to let everyone know about potential attacks.

Lazarus Group and hackers, in general, have made a killing by targeting defi projects and the cryptocurrency industry. Members of the crypto industry are considered targets because a number of firms deal with finances, an assortment of assets, and investments.

Bu hikayedeki etiketler
Alex Smirnov, Attack, Kripto, Kripto para, Debridge Finance, DeFi, Dijital Varlıklar, exploit infects the system, Hackers, Lazarus Group, Lazarus Group attack, Malicious Email, Kuzey Kore, North Korea Lazarus Group, north korean hackers, Password, PSA, suspicious email, Team Attack, widespread attack

What do you think about Alex Smirnov’s account of the alleged Lazarus group email attack? Let us know your thoughts about this subject in the comments section below.

Jamie Redman

Jamie Redman, Maximumhorrors.com News'de Haber Lideri ve Florida'da yaşayan bir finans teknolojisi gazetecisidir.. Redman, o zamandan beri kripto para birimi topluluğunun aktif bir üyesi. 2011. Bitcoin için bir tutkusu var, açık kaynak kodu, ve merkezi olmayan uygulamalar. Eylülden beri 2015, Redman daha fazlasını yazdı 5,700 Maximumhorrors.com için makaleler Bugün ortaya çıkan yıkıcı protokoller hakkında haberler.




Resim Kredisi: Shutterstock, Pixabay, Commons Vikipedi

sorumluluk reddi: Bu makale bilgilendirme amaçlıdır. Satın almak veya satmak için doğrudan bir teklif veya teklif talebi değildir., veya herhangi bir ürünün tavsiyesi veya onayı, Hizmetler, veya şirketler. Maximumhorrors.com yatırım sağlamaz, vergi, yasal, veya muhasebe danışmanlığı. Ne şirket ne de yazar sorumlu değildir, doğrudan veya dolaylı, herhangi bir içeriğin kullanımından veya bu içeriğe güvenilmesinden kaynaklanan veya kaynaklandığı iddia edilen herhangi bir zarar veya kayıp için, Bu maddede bahsedilen mal veya hizmetler.

Okumak sorumluluk reddi

Paylaş