APT-C-26 (Lazarus)组织对数字货币交易所的最新攻击预警

2019-03-29 • Qihoo360 • APT-C-26 (Lazarus) group's latest attack warning on digital currency exchanges •

https://www.secrss.com/articles/9511

Thumbnail for APT-C-26 (Lazarus)组织对数字货币交易所的最新攻击预警

360 researchers linked APT-C-26, identified in the excerpt as Lazarus, to continued attacks against cryptocurrency exchanges and related users. The group allegedly registered wb-invest.net and wb-bot.org in October 2018, then used them to present a malicious automated trading application called Worldbit-bot as legitimate software. Worldbit-bot was described as modified from the open-source Qt Bitcoin Trader project and as using the same attack framework as the earlier CelasTrade Pro campaign, with changes mainly in parameters and keys. The reported phishing activity targeted exchange staff in suspected January and March 2019 operations to enable cryptocurrency theft, showing a mature and repeated tradecraft pattern against blockchain-sector victims.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 03ef7dec218e815a6eb399e3b559a89… 2019-03-29 2020-01-08
HASH 54c6107c09f591a11e5e347acad5b47… 2019-03-29 2020-01-08
HASH 170fac9faef1a8abd728336d1f25a0f… 2019-03-29 2020-01-08
DOMAIN wb-invest.net 2019-03-29 2019-03-29
DOMAIN wb-bot.org 2019-03-29 2019-03-29

Related Actors

Related Reports

« Back