North Korean Hackers Steal Cryptocurrency Using Cloud Services
2023.03.28 19:29
North Korean Hackers Steal Cryptocurrency Using Cloud Services
By Kristina Sobol
Budrigannews.com – A report from cybersecurity service Mandiant has revealed that the North Korean cybercrime operator APT43 is laundering cryptocurrency through the use of cloud computing. The North Korean group uses “stolen crypto to mine for clean crypto,” according to the researchers.
Since 2018, Mandiant, a subsidiary of Google, has been following the North Korean Advanced Persistent Threat (APT) group, but it has only recently “graduated” the group to a distinct identity. The group was referred to by Mandiant as a “major player” that frequently collaborated with other groups.
Mandiant discovered that APT43 was likely raising funds for the North Korean regime and funding itself through its illegal operations, despite the fact that its primary activity was spying on South Korea. Clearly the gathering has been fruitful in those pursuits:
“APT43 steals and launders sufficient cryptocurrency to purchase operational infrastructure in a manner aligned with North Korea’s juche state ideology of self-reliance, thereby reducing fiscal strain on the central government,” reads the statement.
The “likely use of hash rental and cloud mining services to launder stolen cryptocurrency into clean cryptocurrency” was discovered by the researchers.
@Mandiant has graduated a new prolific group #APT43 which generally aligns to #kimsuky. Read more in the blog/report/webinar:https://t.co/GY2sx2wlSehttps://t.co/VZbvGUYqKHhttps://t.co/5Mvk740woW
Cloud mining and hash rental both involve renting capacity for crypto mining. Mandiant says that they let you mine cryptocurrency “to a wallet chosen by the buyer without any blockchain-based association to the buyer’s original payments.”
Mandiant discovered the group’s payment methods, aliases, and addresses for purchases. The group accepted payments through PayPal, American Express cards, and “Bitcoin likely derived from previous operations.”
Additionally, APT43 was linked to the use of Android malware to steal the credentials of Chinese cryptocurrency loan applicants. Additionally, the group manages a number of spoof websites for the purpose of targeted credential harvesting.
Numerous crypto heists, including the most recent Euler theft of over $195 million, have been linked to North Korea. The United Nations estimates that North Korean hackers made a record haul of $630 million to over $1 billion in 2022. Chainalysis estimated that amount to be at least $1.7 billion.
More:
U. S. court ruled on class action lawsuit against bZX DAO
Sam Bankman-Fried Faces New Charges with Chinese Officials
Former FTX owner was banned from using messengers under house arrest