IMG-LOGO

North Korean hackers deploy ‘Durian’ malware, targeting crypto firms

News Feed - 2024-05-13 11:05:57

Tom Mitchelhill6 hours agoNorth Korean hackers deploy ‘Durian’ malware, targeting crypto firmsThe state-backed North Korean hacking group Kimsuky reportedly used a new malware variant to target at least two South Korean crypto firms.4513 Total views19 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksNorth Korean hackers are reportedly utilizing a “striking” new malware variant dubbed “Durian” to launch attacks on South Korean crypto firms.


The North Korean hacking group Kimsuky used the new malware in a series of targeted attacks on at least two cryptocurrency firms so far, according to a May 9 threat report from cybersecurity firm Kaspersky.


This was done through a “persistent” attack by exploiting legitimate security software used exclusively by crypto firms in South Korea.Source: Kaspersky


The previously unknown Durian malware acts as an installer that deploys a continued stream of malware, including a backdoor known as “AppleSeed,” a custom proxy tool known as LazyLoad and other legitimate tools such as Chrome Remote Desktop.


“Durian boasts comprehensive backdoor functionality, enabling the execution of delivered commands, additional file downloads, and exfiltration of files,” wrote Kaspersky.


Additionally, Kaspersky noted that LazyLoad was also used by Andariel, a sub-group within fellow North Korean hacking consortium Lazarus Group — suggesting a “tenuous” connection between Kimsuky and the more notorious hacking group.


Related:North Korean Lazarus hacker group using LinkedIn to target and steal assets: Report


First emerging in 2009, Lazarus has established itself as one of the most notorious groups of crypto hackers.


On April 29, independent blockchain sleuth ZachXBT revealed that the Lazarus group had successfully laundered over $200 million in ill-gotten crypto between 2020 and 2023.


The Lazarus Group is accused of stealing over $3 billion in crypto assets in the six years leading up to 2023.


Lazarus was credited with stealing over 17% — a little over $309 million — of the total stolen funds in 2023. Throughout 2023, more than $1.8 billion worth of crypto was lost to hacks and exploits, according to a Dec. 28 report by Immunefi.


Magazine:Lazarus Group’s favorite exploit revealed — Crypto hacks analysis# Bitcoin# Blockchain# Cryptocurrencies# Business# South Korea# North Korea# Scams# HacksAdd reaction