2018-02
Group-IB listed City Union Bank in India among Lazarus-attributed SWIFT theft cases and reported a $1.87 million loss in the same financial-sector campaign set that included Banco de Chile, Cosmos Bank, Bank of Valletta, and Punjab National Bank. The evid…
🇮🇳 India
#Finance
#SWIFT
#FinancialGain
2018-02
Group-IB listed Punjab National Bank in India among Lazarus-attributed SWIFT incidents from early 2018 in its financial-sector threat reporting. The report places the case in a broader North Korea-linked pattern of prepared SWIFT cash-out operations again…
🇮🇳 India
#Finance
#SWIFT
#FinancialGain
2018-01
Coincheck published an incident notice after restricting NEM deposits, then suspending NEM trading and withdrawals, pausing withdrawals across handled currencies including JPY, halting most altcoin trading, and stopping several fiat deposit methods while …
🇯🇵 Japan
#Cryptocurrency
#FinancialGain
2018-01
In January 2018, Canadian transit agency Metrolinx confirmed a cyberattack traced to a North Korean source. The intrusion breached a firewall but affected a system not tied to customer data, employee data, or safety systems; Metrolinx said it detected and…
🇨🇦 Canada
#Transportation
#Espionage
2018-01
Bancomext appears in reporting on 2018 Mexican banking and wire-transfer payment-system incidents, where attackers were discussed in the context of compromise paths involving concentrators, servers, developers, contractors, and internal banking networks. …
🇲🇽 Mexico
#Finance
#SWIFT
#FinancialGain
2018-01
A private Costa Rican financial institution was targeted in January 2018 in an attempted USD 19 million theft. Carnegie's financial-sector timeline and UN Panel reporting linked the case to DPRK-affiliated actors, placing it within the wider North Korean …
🇨🇷 Costa Rica
#Finance
#FinancialGain
2017-12
Proofpoint described RatankbaPOS as part of financially motivated Lazarus Group activity centered on cryptocurrency and POS-related malware operations. The reporting connected RatankbaPOS with PowerRatankba downloaders, multiple delivery formats including…
🇰🇷 Korea, Republic of
#Finance
#DataBreach
2017-12
Youbit was listed among South Korean cryptocurrency-exchange hacking incidents in reporting that described rising unauthorized withdrawals, unresolved police investigations, and the difficulty of tracing blockchain-enabled thefts through international coo…
🇰🇷 Korea, Republic of
#Cryptocurrency
#FinancialGain
2017-12
NiceHash was described as a cryptocurrency-mining marketplace theft linked to Hidden Cobra, with the intrusion beginning through social engineering that impersonated a company system engineer and mimicked a Google Docs weekly-report invitation sent via an…
🇸🇮 Slovenia
#Cryptocurrency
#FinancialGain
2017-10
Marine Chain was a Hong Kong-registered blockchain maritime investment platform investigated as a DPRK-linked cryptocurrency and sanctions-evasion scheme, with reporting noting at least one DPRK individual behind the project and concerns that tokenized sh…
🇸🇬 Singapore
#Cryptocurrency
#FinancialGain
2017-10
ESET attributed attacks against a Central American online casino to Lazarus, citing overlapping toolsets, telemetry, Lazarus-linked malware, and shared static characteristics. The intrusions used service-oriented NukeSped backdoors, session hijacking, cre…
#Cryptocurrency
#FinancialGain
2017-10
A Tunisian financial institution was targeted in October 2017 in an attempted USD 60 million theft. Carnegie's financial-sector timeline and UN Panel reporting linked the case to DPRK-affiliated actors, making it part of the broader North Korean bank-thef…
🇹🇳 Tunisia
#Finance
#FinancialGain
2017-10
Hermes ransomware appeared in DPRK-relevant activity around the 2017 Far Eastern International Bank heist, where BAE Systems observed Hermes alongside known Lazarus tools and assessed it may have served as distraction or cover during SWIFT-connected theft…
🇹🇼 Taiwan
#Finance
#FinancialGain
2017-10
Far Eastern International Bank was targeted in an October 2017 cyber-enabled heist that abused systems connected to the SWIFT network and attempted unauthorized overseas transfers, with McAfee reporting spear-phishing, backdoor malware, credential harvest…
🇹🇼 Taiwan
#Finance
#ATM
#SWIFT
#FinancialGain
2017-09
Coinis was cited in reporting on Lazarus-linked cryptocurrency exchange intrusions after attackers allegedly stole a code-signing certificate in the Coinis/WaveString breach, signed malware disguised as an OpenSSL library, and pushed malicious files throu…
🇰🇷 Korea, Republic of
#Cryptocurrency
#FinancialGain