Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto!

Share This Post

Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto!

The post Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto! appeared first on Coinpedia Fintech News

Lazarus APT, especially its subgroup BlueNoroff, is attributed to the professional hack attacks on the financial sector, especially those related to cryptocurrencies. This North Korean-linked cyber group has conducted numerous attacks of high profile targeting organizations and businesses, and using sophisticated malware and exploits. 

Three of its tools, namely Manuscrypt, Cutwail, and Turk, have made it possible for over 50 successful campaigns to take place effectively since the year 2013.

Recent Attack Campaign: An Analysis of the Detankzone Exploit

Cybersecurity analysts with Kaspersky in May 2024 pinpointed a Manuscrypt in a Russian system that originated from detankzone[.]com. Though rationalizing itself as a genuine DeFi NFT game, this site was hiding a zero-day Chrome vulnerability. 

The exploit was implanted into a weakness in the V8 JavaScript engine that allows the attackers to take full control of the victim’s computer the moment they visit the site. When Kaspersky reported the case, Google immediately dealt with this critical bug and closed all related fake web pages.

Social Engineering Tactics: Social Media Identity Cloning

Adding to this, Lazarus utilized social engineering and opened fake LinkedIn and X (previously Twitter) accounts to endorse a fake game called “DeTankZone.” DeFiTankLand was another real game whose source was used to release a faithful copy of a game demo, trusting which users downloaded malware. 

This blended approach emphasizes Lazarus’ flexibility in switching between technical and social approaches to overcome crypto space defenses.

A New & Evolving Danger to Crypto Investors

What is crucial for understanding this campaign is that Lazarus is still capable of evading such cutting-edge security protections using zero-day vulnerabilities along with social engineering approaches. 

The event remains relevant to emphasize on the stock and alertness, updates of the applications, and the cautious tendency of the clients, who are involved in cryptocurrency investments, as the threat actors do not stop evolving and improving techniques of attacks.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Virtuals Launches AI Agent on Ronin Blockchain With JAIHOZ Token

Ronin, a blockchain designed for Web3 gaming, has partnered with Virtuals Protocol to incorporate an artificial intelligence (AI) agent into its platform Blockchain Collaboration Brings JAIHOZ Token

Dogecoin Whales Go on 470 Million DOGE Buying Spree Amid Bullish Recovery In Major Metrics

Surprisingly, Dogecoin whales are on a massive buying spree, as new reports show that these large-scale investors have added a whopping 470 million DOGE into their portfolios This substantial

Kenya Moves To Legalize Crypto – Details

The Republic of Kenya is currently making moves to create a legal framework for crypto operations Interestingly, this rather exciting development comes shortly after the International Monetary Fund

‘Dino Coins’ Roar Back: XRP, XLM, and ADA Lead the Charge in Weekend Gains

Coins colloquially labeled as “dino coins” have dominated the weekend’s crypto gains, with XRP, XLM, and ADA enjoying substantial upticks over the past 24 hours Leading this

Ethereum Sees $1.4 Billion In Exchange Outflows This Week – Strong Accumulation Trend?

Ethereum has faced a challenging start to the year, shedding 15% from its recent local highs and dipping to a low of $3,157 The altcoin leader’s decline comes amid heightened market volatility and

Crypto ATM Numbers Approach Record High: A Steady Recovery After Industry Shocks

After a turbulent 2023 followed by a recovery in 2024, the global count of crypto-automated teller machines (ATMs) is inching closer to its former high of 39,958, achieved on Dec 1, 2022 Crypto ATMs