Fun

News Feed - 2023-11-02 06:11:00

Tom Blackstone3 hours agoLazarus used ‘Kandykorn’ malware in attempt to compromise exchange — ElasticLazarus members posed as engineers and fooled exchange employees into downloading difficult-to-detect malware.891 Total views18 Total sharesListen to article 0:00NewsJoin us on social networksLazarus Group used a new form of malware in an attempt to compromise a crypto exchange, according to an Oct. 31 report from Elastic Security Labs.


Elastic has named the new malware “Kandykorn” and the loader program that loads it into memory “Sugarload,” as the loader file has a novel “.sld” extension in its name. Elastic did not name the exchange that was targeted.


Crypto exchanges have suffered a rash of private-key hacks in 2023, most of which have been traced to the North Korean cybercrime enterprise Lazarus Group.Kandykorn infection process. Source: Elastic Security Labs


According to Elastic, the attack began when Lazarus members posed as blockchain engineers and targeted engineers from the unnamed crypto exchange. The attackers made contact on Discord, claiming they had designed a profitable arbitrage bot that could profit from discrepancies between the prices of cryptocurrencies on different exchanges.


The attackers convinced the engineers to download this “bot.” The files in the program’s ZIP folder had disguised names like “config.py” and “pricetable.py” that made it appear to be an arbitrage bot.


Once the engineers ran the program, it executed a “Main.py” file that ran some ordinary programs as well as a malicious file called “Watcher.py.” Watcher.py established a connection to a remote Google Drive account and began downloading content from it to another file named testSpeed.py. The malicious program then ran testSpeed.py a single time before deleting it in order to cover its tracks.


During the single-time execution of testSpeed.py, the program downloaded more content and eventually executed a file that Elastic calls “Sugarloader.” This file was obfuscated using a “binary packer,” Elastic stated, allowing it to bypass most malware detection programs. However, they were able to discover it by forcing the program to stop after its initialization functions had been called, then snapshotting the process’ virtual memory.


According to Elastic, it ran VirusTotal malware detection on Sugarloader, and the detector declared that the file was not malicious.


Related:Crypto firms beware: Lazarus’ new malware can now bypass detection


Once Sugarloader was downloaded onto the computer, it connected to a remote server and downloaded Kandykorn directly into the device’s memory. Kandykorn contains numerous functions that can be used by the remote server to perform various malicious activities. For example, the command “0xD3” can be used to list the contents of a directory on the victim’s computer, and “resp_file_down” can be used to transfer any of the victim’s files to the attacker’s computer.


Elastic believes that the attack occurred in April 2023. It claims that the program is probably still being used to perform attacks today, stating:“This threat is still active and the tools and techniques are being continuously developed.”


Centralized crypto exchanges and apps suffered a rash of attacks in 2023. Alphapo, CoinsPaid, Atomic Wallet, Coinex, Stake and others have been victims of these attacks, most of which seem to have involved the attacker stealing a private key from the victim’s device and using it to transfer customers’ cryptocurrency to the attacker’s address. 


The United States Federal Bureau of Investigation has accused the Lazarus Group of being behind the Coinex hack, as well as performing the Stake attack and others.# Blockchain# Security# Adoption# Hackers# Cybercrime# Cybersecurity# Hacks# ExchangesAdd reactionAdd reactionRead moreCrypto horrors: Tales of lost Bitcoin walletsFrom payments to DeFi: A closer look at the evolving stablecoin ecosystemCrypto exchange Upbit targeted by hackers 159K times in H1: Report

News Feed

Bitcoin Evolution: Wanna Make $1 Million in 2 Months Like Prince Harry and Meghan Markle? It’s a Scam
Bitcoin Evolution: Wanna Make $1 Million in 2 Months Like Prince Harry and Meghan Markle? It"s a ScamA bitcoin investment scheme has reportedly claimed that Prince Harry and Meghan
Why is the crypto market up today?
Nancy Lubale4 hours agoWhy is the crypto market up today?The crypto market is up today as bears succumb to heavy liquidations and improvements in the stock market boost investor sentiment.389 Total viewsListen to article
University of Tokyo to Offer Engineering Courses in the Metaverse
University of Tokyo to Offer Engineering Courses in the Metaverse The University of Tokyo will offer a series of engineering courses using metaverse tech. The courses, which are pr
Up to 30% of Bitcoin Miners Close Shop as Business Turns Unprofitable After Halving
Up to 30% of Bitcoin Miners Close Shop as Business Turns Unprofitable After HalvingAbout a third of Bitcoin (BTC) mining firms may already be switching off their machines as the bus
Illegal to Own Gold? Hedge Fund Manager Warns Governments May Ban Gold Ownership
Illegal to Own Gold? Hedge Fund Manager Warns Governments May Ban Gold OwnershipA well-known hedge fund manager has warned that governments may ban private gold ownership. He explai
Bakkt to Launch Options on Its Bitcoin Futures Dec. 9
The Intercontinental Exchange (ICE) is launching bitcoin options contracts through its subsidiary Bakkt. Bakkt announced Thursday that it would “launch the first regulated opt
Amaka Nwaokocha2 hours agoFTX suspends user accounts amid Kroll cyber breach concernsFTX took the decision as a proactive measure to prevent any potential future incidents or additional harm following the recent hack.492
Undeterred by Fears of a Banking Crisis, ECB Raises Interest Rates by 50bps
Undeterred by Fears of a Banking Crisis, ECB Raises Interest Rates by 50bps The European Central Bank (ECB) has convened to raise three of its key interest rates by 50bps (0.5%), f
Why is Ethereum (ETH) price down today?
Yashu Gola9 hours agoWhy is Ethereum (ETH) price down today?ETH price dropped over 8% in the past 24 hours, driven by a growing sell-the-news sentiment following the launch of Ethereum ETFs.1405 Total views1 Total shares
Hermi De Ramos14 hours agoCardano upgrade delays tied to measured academic approach — CEOCardano Foundation CEO Frederik Gregaard told Cointelegraph that the pieces of research that the network has “spent years of do
No Backdoor on Human Rights: Why Encryption Cannot Be Compromised
No Backdoor on Human Rights: Why Encryption Cannot Be Compromised In April 2019, the UK issued an Online Harms White Paper to announce its campaign to rein in “harmful spee
South African Financial Sector Regulator Declares Crypto Assets a Financial Product
South African Financial Sector Regulator Declares Crypto Assets a Financial Product According to a general notice published in a government gazette, crypto assets are now treated a