Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto!

Share This Post

Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto!

The post Crypto Hack Exposed: How Lazarus APT Is Using DeFi Games to Steal Your Crypto! appeared first on Coinpedia Fintech News

Lazarus APT, especially its subgroup BlueNoroff, is attributed to the professional hack attacks on the financial sector, especially those related to cryptocurrencies. This North Korean-linked cyber group has conducted numerous attacks of high profile targeting organizations and businesses, and using sophisticated malware and exploits. 

Three of its tools, namely Manuscrypt, Cutwail, and Turk, have made it possible for over 50 successful campaigns to take place effectively since the year 2013.

Recent Attack Campaign: An Analysis of the Detankzone Exploit

Cybersecurity analysts with Kaspersky in May 2024 pinpointed a Manuscrypt in a Russian system that originated from detankzone[.]com. Though rationalizing itself as a genuine DeFi NFT game, this site was hiding a zero-day Chrome vulnerability. 

The exploit was implanted into a weakness in the V8 JavaScript engine that allows the attackers to take full control of the victim’s computer the moment they visit the site. When Kaspersky reported the case, Google immediately dealt with this critical bug and closed all related fake web pages.

Social Engineering Tactics: Social Media Identity Cloning

Adding to this, Lazarus utilized social engineering and opened fake LinkedIn and X (previously Twitter) accounts to endorse a fake game called “DeTankZone.” DeFiTankLand was another real game whose source was used to release a faithful copy of a game demo, trusting which users downloaded malware. 

This blended approach emphasizes Lazarus’ flexibility in switching between technical and social approaches to overcome crypto space defenses.

A New & Evolving Danger to Crypto Investors

What is crucial for understanding this campaign is that Lazarus is still capable of evading such cutting-edge security protections using zero-day vulnerabilities along with social engineering approaches. 

The event remains relevant to emphasize on the stock and alertness, updates of the applications, and the cautious tendency of the clients, who are involved in cryptocurrency investments, as the threat actors do not stop evolving and improving techniques of attacks.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Retail investors dominate demand for spot Bitcoin ETFs – Binance Research

Retail investors are leading the charge in the adoption of spot Bitcoin exchange-traded funds (ETFs), accounting for 80% of the total demand, according to a recent report by Binance Research

US Government’s $20M Crypto Breach: How Most Was Returned Within 24 Hours

According to blockchain explorer firm Arkham Intelligence, a significant portion of the US government’s allegedly seized crypto has made its way back Sudden Shift in Seized Crypto Sparks

XRP Network Activity Soars: Can Price Break Free from Resistance?

The post XRP Network Activity Soars: Can Price Break Free from Resistance appeared first on Coinpedia Fintech News XRP’s network activity is making waves as it hits a new high in active sending

Denmark Mulls Taxing Unrealized Crypto Profits Beginning 2026

Denmark is considering taxing unrealized gains on crypto assets to minimize the difference in tax treatment between digital assets and traditional asset holders Denmark Eyes Taxing Unrealized Crypto

Crypto Analyst Says Ethereum Will Outperform Bitcoin And Solana, Is $12,000 Possible?

A top crypto analyst has issued a bold prediction for Ethereum, forecasting it will outperform both Bitcoin and Solana in the coming months Taking to social media platform X, a crypto analyst known

Rep. Hill Slams Gensler’s Approach To Crypto Regulation, Demands New SEC Chair In 2025

In a recent interview on the Think Crypto Podcast, US Representative French Hill expressed his vision for a new leadership at the US Securities and Exchange Commission (SEC) in 2025, emphasizing the