CoinsPaid claims North Korean hacking group used fake job interview to steal $37M

Share This Post

Hackers attempted to infiltrate CoinsPaid infrastructure directly starting in March 2023, but switched their approach to targeting individuals through fake high-salary job offers.

Estonia-based cryptocurrency payments firm CoinsPaid suspects North Korean hackers with the Lazarus Group gained access to its systems through fake recruiters targeting employees.

In an Aug. 7 blog post, CoinsPaid said an exploit which allowed hackers to steal more than $37 million on July 22 was the result of tricking one employee into downloading software during a fake job interview, having them believe they were completing a technical task. The firm reported that the worker responded to a job offer put out by hackers and downloaded the malicious code, allowing the bad actors to steal information and give them access to CoinsPaid’s infrastructure.

“Having gained access to the CoinsPaid infrastructure, the attackers took advantage of a vulnerability in the cluster and opened a backdoor,” said CoinsPaid. “The knowledge perpetrators gained at the exploration stage enabled them to reproduce legitimate requests for interaction interfaces with the blockchain and withdraw the company’s funds from our operational storage vault.”

Related: Curve hacker behind $61M heist begins returning funds

In its July 26 post-mortem report of the hack, CoinsPaid said it suspected Lazarus Group. Prior to the $37-million exploit, the hackers had made several attempts to infiltrate the platform starting in March 2023, but switched their approach to “highly sophisticated and vigorous social engineering techniques” after multiple failures — targeting individual workers rather than the company itself.

Tracing the funds stolen from CoinsPaid on July 22. Source: CoinsPaid

CoinsPaid said it had partnered with blockchain security company Match Systems to track the stolen funds, the majority of which were transferred to SwftSwap. According to the firm, many aspects of the hackers’ transactions mirrored those of the Lazarus Group, as in the $35-million hack of Atomic Wallet in June. The company was continuing to monitor any movement of the funds as of Aug. 7. 

Magazine: Should crypto projects ever negotiate with hackers? Probably

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ether Liquidity Plummets 40% On Exchanges After ETF Debut

Liquidity of Ether on US exchanges has plunged as much as 40% since the first spot Ether exchange-traded funds entered the market on July 23, 2024 Related Reading: Cardano Bull Sees ADA Jumping

UBS: European Real Estate Markets Enter New Cycle

UBS reported on Thursday that European real estate markets appear to be entering a new investment cycle, with key indicators pointing to stabilization “A new cycle starts,” the report

Bitcoin Plunges Under $54K As Weak US Jobs Data Shakes Markets

Bitcoin fell below $54,000 on September 6, 2024, after cruising earlier in the day to $57,000 following the US nonfarm payrolls The report showed that the economy added only 142,000 jobs in August,

Mark Cuban Warns Kamala Harris’ Unrealized Gains Tax Will Kill Stock Market

Billionaire Mark Cuban warned that taxing unrealized gains would “kill” the stock market but believes Vice President Kamala Harris would not prioritize this policy While Harris supports

Helium (HNT) Network Expansion Fuels 13% Gains Despite Faltering Market

Helium (HNT) defeats the market’s bearishness as its new developments drive hype for the long term According to CoinGecko, HNT rose by 13% despite the market’s continued fall in the short term

20 Government Agencies in US, South Korea, and Japan Tackle North Korean Crypto Threats

The United States, Japan, and the Republic of Korea (ROK) held their third Trilateral Diplomatic Working Group meeting on Friday in Seoul to address North Korean cyber threats Led by US Deputy