North Korea aims 'TraderTraitor' malware at cryptocurrency workers
Full article576 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Cybersecurity and Infrastructure Security Agency is attributing the campaign to hackers known as the Lazarus Group.
North Korean state-backed hackers are phishing cryptocurrency company employees in order to gain access to systems that allow them to make fraudulent trades, according to an advisory Monday from the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.
The technique begins with a large number of email messages to that offer a better job to the employees — a common technique for the North Korean hackers, who are commonly known as the Lazarus Group. The emails urge recipients to click on applications posing as cryptocurrency trading and price prediction tools. They’re actually malware that CISA, which issued the alert with the FBI and Treasury Department, calls “TraderTraitor.”
Once the payload is deployed, cybercriminals can execute commands and send additional malware allowing them to gain access to a victim’s computer and move across a company’s network. The goal is to steal private keys or exploit security gaps that allow for fraudulent blockchain transactions, CISA said.
The warning follows updated sanctions last week against the Lazarus Group for links to a recent $650 million hack of the Ronin network connecting the popular Axie Infinity video game with the Ethereum blockchain. The advanced persistent threat (APT) group has been linked by the U.S. government to North Korea’s Reconnaissance General Bureau (RGB).

Researchers at Israeli security firm ClearSky attributed a similar campaign to the Lazarus Group last year, though it doesn’t appear the attacks share any indicators of compromise with the TraderTraitor malware. Some of the indicators of compromise of TraderTraitor include the application names TokenAIS, CryptAIS and Esilet.
The Lazarus Group has a long history of hacking financial institutions in order to fund North Korea’s nuclear program and skirt heavy Western sanctions. Since 2018, North Korean hackers have deployed several forms of malware posing as legitimate cryptocurrency businesses. In addition to phishing, hackers use social networking to lure victims.
The U.S. government has also blamed Lazarus Group for the hack of Sony Pictures in 2014 and the launch of the WannaCry 2.0 ransomware in 2017.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/tradertraitor-malware-warning-cisa-lazarus-group-north-korea/