REF7001
2023-11-01 • Elastic • Elastic catches DPRK passing out KANDYKORN
Elastic Security Labs disclosed in a November 2023 report an intrusion set it tracks as REF7001, which targeted blockchain engineers at a cryptocurrency exchange platform; Elastic attributed the activity to North Korea and noted overlaps with the Lazarus Group based on techniques, network infrastructure, and code-signing certificates. The attackers impersonated members of the blockchain engineering community on a public Discord server and social-engineered a victim into downloading an archive disguised as a cryptocurrency arbitrage bot. Running the bundled script triggered a multi-stage macOS infection chain involving remotely hosted droppers, an obfuscated loader, and a persistence component that hijacked the legitimate Discord application's launch process, ultimately executing a final-stage payload capable of information gathering, data exfiltration, and arbitrary command execution. The intrusion relied on defense-evasion techniques, including reflective in-memory loading of binaries and a macOS code-signing technique previously linked to the Lazarus Group's 3CX supply-chain compromise.
-
60
Related Actors
-
3
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster