2024-06
Andariel targeted centralized management solutions used by South Korean enterprises, abusing exposed administrator console ports, vulnerable management software, and later supply-chain distribution paths through developers with downstream customers. Linke…
🇰🇷 Korea, Republic of
#SupplyChain
#Technology
2024-06
On June 22, 2024, CoinStats suffered a wallet breach attributed by the company to Lazarus Group or a related nation-state-level organization. The attacker gained unauthorized access across CoinStats infrastructure and service providers, exposing private k…
🇦🇲 Armenia
#Cryptocurrency
#FinancialGain
2024-06
Uwulend, a lending protocol, suffered a $19.4 million hack due to an oracle manipulation attack. The attacker used three transactions to exploit a price discrepancy in Uwulend's oracles, facilitated by a flash loan. Despite a recent security audit, the at…
#Cryptocurrency
#FinancialGain
2024-06
On June 4, centralized cryptocurrency exchange Lykke suffered a security breach that resulted in the theft of over $22 million in crypto assets. The exchange initially halted withdrawals—citing unscheduled maintenance—and was later accused by researcher S…
🇬🇧 United Kingdom
#Cryptocurrency
#FinancialGain
2024-05
In May 2024, Japan’s DMM Bitcoin lost 4,502.9 BTC, worth about $308 million, in a theft attributed by the FBI, DC3, and Japan’s National Police Agency to North Korea-linked TraderTraitor activity. The actors socially engineered a Ginco employee with a mal…
🇯🇵 Japan
#Cryptocurrency
#FinancialGain
2024-05
In April 2024, Microsoft observed Moonstone Sleet deploying FakePenny, a custom ransomware loader and encryptor, against a company the actor had previously compromised in February. Microsoft assessed the deployment as financially motivated and significant…
ZZZ
#FinancialGain
#Defense
2024-05
South Korean police investigated suspected North Korean hacking of personal email accounts belonging to senior Ministry of National Defense officials and military officers, including vice-minister-level officials and generals. Reporting said the incident …
🇰🇷 Korea, Republic of
#Espionage
#Defense
2024-05
AlexLab experienced a $4.3 million exploit due to a compromised private key, impacting their XLink bridge on the BNB network. The attacker used phishing to gain control of the vault keys, allowing them to drain 13.7 million STX, with 3 million STX sent to…
🇸🇬 Singapore
#Cryptocurrency
#FinancialGain
2024-04
Rain disclosed and contained a cryptocurrency exchange security incident after reporting indicated the Bahrain-headquartered platform lost crypto assets in a confirmed exploit, while Rain stated customer fiat and crypto assets remained fully accounted for…
🇧🇸 Bahamas
#Cryptocurrency
#FinancialGain
2024-04
By April 2024, South Korean police and partner agencies reported broad North Korea-linked intrusions against domestic defense contractors and less-secure partner companies, attributed to groups including Lazarus, Andariel, and Kimsuky. The attackers sough…
🇰🇷 Korea, Republic of
#Espionage
#Defense
2024-04
Avast reported that GuptiMiner hijacked the eScan antivirus update mechanism to distribute backdoors and coinminers, turning trusted security software updates into a supply-chain delivery path. The campaign included a multi-modular backdoor capable of rec…
🇮🇳 India
#SupplyChain
#Technology
2024-03
Solareum, a Telegram trading bot, shut down days after a security breach involving wallet drainers that reportedly affected more than 300 Solana users and resulted in the loss of more than 2,800 SOL. Linked forfeiture evidence also describes a USDT seizur…
🇦🇪 United Arab Emirates
#Cryptocurrency
#FinancialGain
2024-03
Munchables suffered a Blast-chain exploit in which linked analysis describes contract manipulation, including a backdoor implementation contract that was later replaced with normal logic to obscure the attacker’s tracks. Reporting discussed possible DPRK …
🇺🇸 United States
#Cryptocurrency
#Suspicious
#FinancialGain
2024-03
Kimsuky distributed malware disguised as installation files for South Korean public institutions, using a dropper signed with a valid domestic company certificate to unpack and execute the Endoor backdoor. The linked evidence connects the activity to Kims…
🇰🇷 Korea, Republic of
#SupplyChain
#Technology
2024-01
Kimsuky used trojanized security or software installers masquerading as legitimate Korean software packages, including TrustPKI and NX_PRNMAN, to deploy Troll Stealer/TrollAgent and related backdoor malware. The installers executed normal setup files as d…
🇰🇷 Korea, Republic of
#SupplyChain
#Technology