Posts

Showing posts with the label hacks

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

Image
Lazarus members posed as engineers and fooled exchange employees into downloading difficult-to-detect malware. Lazarus Group used a new form of malware in an attempt to compromise a crypto exchange , according to an October 31 report from Elastic Security Labs. Elastic has named the new malware “KANDYKORN” and the loader program that loads it into memory “SUGARLOAD,” as the loader file has a novel “.sld” extension in its name. Elastic did not name the exchange that was targeted. Crypto exchanges have suffered a rash of private-key hacks in 2023, most of which have been traced to the North Korean cybercrime enterprise, Lazarus Group. KANDYKORN infection process. Source: Elastic Security Labs. According to Elastic, the attack began when Lazarus members posed as blockchain engineers and targeted engineers from the unnamed crypto exchange. The attackers made contact on Discord, claiming they had designed a profitable arbitrage bot that could profit from discrepancies between prices ...

US state agency issues alert on crypto fraud happening over social media

Image
Vermont issued the investor alert after a 74-year-old man lost his life savings of over $340,000 in a crypto fraud orchestrated over Instagram and Telegram. The Vermont Department of Financial Regulation (DFR) — the United States state of Vermont’s financial regulatory agency — warned citizens against rising crypto investment frauds perpetrated over popular social media sites. On June 25, 74-year-old Naum Lantsman lost his life savings of $340,000 to a crypto scam orchestrated over Instagram and Telegram. The DFR referenced the incident as it emphasized “the need for Vermonters to exercise extreme caution and vigilance when using or investing in cryptocurrency.” A snippet of Vermont’s investor alert against crypto scams. Source: dfr.vermont.gov Instagram has been rated as the top platform connected to crypto fraud by the Federal Trade Commission (FTC), which is also true for Lantsman. His initial contact with the crypto scammer happened over Instagram, wherein he came across a post fr...

Tornado Cash governance control set to be restored as voters approve proposal

Image
A total of 517,000 token votes favored the proposal, with none opposing it. The governance tokenholders of Tornado Cash will soon regain control over the protocol’s operations, thanks to an unexpected proposal put forward by the attacker. This development allows the community to regain authority and steer the protocol toward recovery and improved security measures. On May 26, the proposal to restore control to the original governance tokenholders of Tornado Cash passed successfully. A total of 517,000 token votes favored the proposal , with none opposing it. This resolution brings a swift conclusion to a governance takeover that, fortunately, did not impact the protocol itself, but did lead to the theft of specific governance tokens. A screenshot showing the voting results. Source: Tornado Cash By successfully orchestrating a takeover of the protocol’s governance system, the attacker maneuvered a malicious proposal that granted them 1.2 million votes. Leveraging this significant...

BitKeep CEO says some users’ private keys remain at risk after exploit

The blockchain executive urged users who downloaded the BitKeep 7.2.9. APK malware to transfer their assets immediately. According to a letter posted on Chinese block Chain news publisher Odaily.com on Dec. 27, Kevin Como, the anonymous CEO of BitKeep, warned that users’ private keys are still at risk after a security incident on Dec. 26 led to over $13 million in losses at the time of publication. BitKeep is one of the more popular noncustodial, decentralized finance multichain wallets with over 6 million users . Specifically, Como wrote: “This was a large and atrocious hacker attack incident. The BitKeep APK 7.2.9 (Android Package Kit) installation package was hijacked and swapped by the hacker, and as a result, some users already installed the APKs that were planted malware by the hackers, leading to a leak of users’ private keys.” Como urged users who had already downloaded the Android APK 7.2.9. to transfer their digital assets to a new wallet. “It is probable that [these wa...