In a recent cyber scheme, North Korean hackers, disguising themselves as journalists and South Korean government entities, have been engaging in cryptocurrency theft.
Crypto Infiltration:Between March and October, these hackers, posing as officials and journalists, targeted approximately 19 victims, employing tactics to steal cryptocurrency.
User ID Theft:The perpetrators expropriated user IDs and profiles from 19 victims to gain unauthorized access to their cryptocurrency trading accounts.
Mining Operations:In addition to ID theft, the hackers executed crypto mining programs on over 147 proxy servers under their control.
Previous Attacks Raise Concerns:Less than a year ago, the same hackers utilized malicious software to pilfer cryptocurrencies, raising concerns about potential property and asset losses.
Ransomware Distribution:During their previous attack, the hackers distributed ransomware, coercing victims to pay money and valuables to regain control of their virtual assets.
Countermeasures:To counteract the threat, authorities, in collaboration with the Korea Internet & Security Agency, shut down 42 fake websites operated by the North Korean hackers. This joint effort aims to prevent more individuals from falling victim to such deceptive tactics.
Government Action:The police are set to provide the government’s intelligence and cyber experts with a comprehensive list of the servers used by the hackers. This collaboration aims to strengthen cybersecurity and prevent further illicit activities.
While authorities are actively responding to the cyber threats, the recurring nature of these attacks raises concerns about the vulnerability of crypto investors to such deceptive schemes.