2022-10
Algorand was listed among cryptocurrency incidents in ZachXBT reporting that traced roughly $200 million stolen across 25 hacks from August 2020 to October 2023 to Lazarus Group, also described as Bluenoroff or APT38. The linked analysis described a DPRK-…
🇸🇬 Singapore
#Cryptocurrency
#FinancialGain
2022-09
GERA reported that a private-key leak allowed attackers to transfer ownership of the token smart-contract deployer, create additional contracts, mint unauthorized GERA on Ethereum and Binance, send tokens to decentralized exchanges, and move tokens to cen…
🇺🇸 United States
#Cryptocurrency
#FinancialGain
2022-08
Nomad Bridge was compromised through an implementation bug in the Replica contract that allowed forged messages to pass authentication because an unproven message could map to bytes32(0) and acceptableRoot(bytes32(0)) returned true. Post-incident material…
🇺🇸 United States
#Cryptocurrency
#FinancialGain
2022-07
North Korean state-sponsored actors, with later reporting linking a 2021 case to Andariel, used Maui ransomware in a manually operated encryption campaign affecting healthcare and other financially viable organizations in the United States and Japan. The …
🇺🇸 United States, 🇯🇵 Japan
#Healthcare
#FinancialGain
2022-07
DEV-0530, a North Korea-origin ransomware cluster with suspected overlap with PLUTONIUM/Andariel tooling and infrastructure, used H0lyGh0st ransomware against small and midsize businesses from at least September 2021. The campaign encrypted Windows system…
🇺🇸 United States
#FinancialGain
2022-06
In June 2022, Harmony’s Horizon Bridge lost about $100 million in virtual currency after attackers compromised bridge-validator private keys and moved assets including USDC, ETH, USDT, BNB, and other tokens through wallet hopping and Tornado Cash. Harmony…
🇺🇸 United States
#Cryptocurrency
#FinancialGain
2022-04
An Oregon defense company was among the defense-sector targets cited in the U.S. indictment of a North Korean Andariel operator and co-conspirators tied to Maui ransomware-funded intrusion infrastructure. The broader campaign allegedly exploited unpatched…
🇺🇸 United States
#DataBreach
#Defense
2022-04
Robins Air Force Base was identified as one of the U.S. Air Force targets in an alleged Andariel-linked campaign where DPRK operators used infrastructure funded by laundered Maui ransomware payments for additional defense, technology, and government intru…
🇺🇸 United States
#DataBreach
#Defense
2022-04
Randolph Air Force Base was listed among U.S. Air Force and government targets in an alleged Andariel conspiracy tied to DPRK Reconnaissance General Bureau operators who financed further intrusions with laundered Maui ransomware proceeds. The broader acti…
🇺🇸 United States
#DataBreach
#Defense
2022-04
A Michigan defense company was included among U.S. defense, technology, and government targets allegedly compromised by Andariel-linked operators after ransom proceeds from Maui ransomware attacks were laundered and used to lease infrastructure for follow…
🇺🇸 United States
#DataBreach
#Defense
2022-03
In March 2022, Sky Mavis’ Ronin Bridge for Axie Infinity lost 173,600 ETH and 25.5 million USDC, about $624 million, after attackers used compromised validator access to forge withdrawals. Linked analysis says the attack abused Ronin’s validator-approval …
🇻🇳 Viet Nam
#Cryptocurrency
#FinancialGain
2022-03
DeFiance Capital founder Arthur Cheong was targeted in a spear-phishing and social-engineering attack that led to theft of cryptocurrency and NFTs from a sophisticated DeFi user. Linked reporting places the incident in the broader DPRK cryptocurrency-thre…
🇸🇬 Singapore
#Cryptocurrency
#FinancialGain
2022-03
Andariel allegedly targeted a California defense company in follow-on intrusions funded by ransom payments from Maui ransomware attacks against U.S. healthcare organizations. Prosecutors said the actors exploited unpatched known vulnerabilities, including…
🇺🇸 United States
#DataBreach
#Defense
2022-03
Andariel allegedly targeted a Colorado medical clinic as part of a North Korean Reconnaissance General Bureau-linked operation against U.S. healthcare organizations using Maui ransomware. The indictment described extortion of hospitals and health care pro…
🇺🇸 United States
#Healthcare
#FinancialGain
2022-03
Andariel allegedly targeted a Florida hospital in a broader North Korean campaign that used Maui ransomware to hack and extort U.S. hospitals and health care providers. U.S. prosecutors said ransom payments were laundered through China-based facilitators …
🇺🇸 United States
#Healthcare
#FinancialGain