lazarusholic

Everyday is lazarus.dayβ

Brief Analysis on APT Attack through Cryptocurrency Trading Software

2018-08-15, Qihoo360
http://blogs.360.cn/blog/apt-c-26/
#Cryptocurrency #AppleJeus

Contents

APT-C-26 is an APT group that has been active since 2009. According to the research by an overseas security vendor, the group’s earliest attack may be associated with the “Operation Flame” which was a large-scale DDOS attack on Korean government’s website in 2007. Lazarus may also be the group behind the hacking incident of Sony Pictures in 2014, the data breach of the Bank of Bangladesh in 2016 and other infamous attacks such as the “Wannacry” ransomware that swept across the globe in 2017. Since 2017, the group has been expanding its targets of attack and increasingly aimed at economic interests. In earlier attacks, the group mainly targeted the banking system of traditional financial institutions. Now, it has begun to attack global cryptocurrency organizations and related individuals.

Recently, the Advanced Threat Response Team of 360 Core Security discovered an APT attack (code named as APT-C-26) against cryptocurrency institutions and related individuals. …

IoC

aeee54a81032a6321a39566f96c822f5
b054a7382adf6b774b15f52d971f3799
https://www.celasllc.com/checkupdate.php