CryptoCore – Cryptocurrency Exchanges Under Attack
2020-06-26 • Atlas-cybersecurity •
https://atlas-cybersecurity.com/cyber-threats/cryptocore-cryptocurrency-exchanges-under-attack/
Atlas Cybersecurity summarizes ClearSky reporting on CryptoCore, a cryptocurrency exchange theft group active since at least 2018. The group primarily targeted exchanges and related companies in the United States and Japan through reconnaissance and spear phishing, with thefts assessed at roughly $70 million. The article describes attempts to reach exchange wallets through executives' personal accounts or corporate email, followed by supply chain style access against organizations connected to the target exchanges; it does not attribute the activity to DPRK or Lazarus.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | linkpc.net | 2020-06-24 | 2026-01-14 |
| DOMAIN | theworkpc.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | krypitalvc.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | onmypc.org | 2020-06-24 | 2020-06-26 |
| DOMAIN | kozow.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | dynu.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | itemdb.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | itsaol.com | 2020-06-24 | 2020-06-26 |
| DOMAIN | publicvm.com | 2017-12-19 | 2020-06-26 |