REF7001

2023-11-01 • ElasticElastic catches DPRK passing out KANDYKORN

Elastic Security Labs disclosed in a November 2023 report an intrusion set it tracks as REF7001, which targeted blockchain engineers at a cryptocurrency exchange platform; Elastic attributed the activity to North Korea and noted overlaps with the Lazarus Group based on techniques, network infrastructure, and code-signing certificates. The attackers impersonated members of the blockchain engineering community on a public Discord server and social-engineered a victim into downloading an archive disguised as a cryptocurrency arbitrage bot. Running the bundled script triggered a multi-stage macOS infection chain involving remotely hosted droppers, an obfuscated loader, and a persistence component that hijacked the legitimate Discord application's launch process, ultimately executing a final-stage payload capable of information gathering, data exfiltration, and arbitrary command execution. The intrusion relied on defense-evasion techniques, including reflective in-memory loading of binaries and a macOS code-signing technique previously linked to the Lazarus Group's 3CX supply-chain compromise.

Related Actors

Related Reports in This Cluster

Top Authors

View REF7001 reports only

View REF7001 reports only