Crypto Core
2020-06-24 • Clearskysec • CryptoCore Group
CryptoCore is a campaign name coined by the Israeli firm ClearSky in a June 2020 report describing a roughly three-year-old operation against cryptocurrency exchanges in Israel, the United States, Europe and Japan in which attackers stole hundreds of millions of dollars worth of crypto wallets; other researchers who examined overlapping activity around the same time suspected a Russian or other Eastern European origin and described the group obtaining access to exchange employees' password manager accounts. The same overlapping activity was also described under related names including CryptoMimic and Dangerous Password, involving spear phishing that lured victims into downloading malicious files, VBS-based command-and-control scripts, and custom RATs and credential stealers. In May 2021, ClearSky published a follow-up report comparing indicators, malware code, and detection-rule matches across its own and other firms' research, concluding with medium-high confidence that the campaign was actually run by North Korea's Lazarus Group, a state-sponsored actor pursuing espionage and cryptocurrency theft, marking what ClearSky described as the first known Lazarus targeting of Israeli organizations.
-
34
Related Actors
-
8
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster