#CoinRush

Incident/Operation

2018-11-01 • Since the hacking of Sony Pictures

Operation Coin Rush was the label applied to cryptocurrency-focused activity observed in 2017–2018 and discussed as suspected Lazarus Group work. The campaign targeted cryptocurrency exchanges and research organizations in South Korea, using malicious Hangul documents disguised with themes such as tax audits, criminal investigations, wallet information, transaction records, and cryptocurrency market analysis. Those documents exploited the Hangul EPS processing vulnerability to run embedded scripts when opened. The activity followed a broader sequence of attacks against Korean institutions and companies, but the attribution remained based on malware relationships and the surrounding Lazarus-linked activity rather than a publicly identified operator.

Tagged Reports

« Back