Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Slow Fog Cosine: Confirmed that the CEX theft incident was attacked by North Korean hacker Lazarus Group, their attack method has been revealed

Slow Fog Cosine: Confirmed that the CEX theft incident was attacked by North Korean hacker Lazarus Group, their attack method has been revealed

Bitget2025/02/23 13:43

The founder of SlowMist, Yu Cosine, posted on social media stating that through evidence analysis and associated tracking, we have confirmed that the attacker in the CEX theft incident is indeed the North Korean hacker organization Lazarus Group. This is a state-level APT attack targeting cryptocurrency trading platforms. We decided to share related IOCs (Indicators of Compromise), which include some cloud service providers and proxies whose IPs were exploited. It should be noted that this disclosure does not specify which platform or platforms are involved, nor does it mention CEX specifically; if there are similarities, it's not impossible.

The attackers used pyyaml for RCE (Remote Code Execution) to deliver malicious code and thus control target computers and servers. This method bypasses most antivirus software scans. After synchronizing intelligence with partners, multiple similar malicious samples were obtained. The main goal of the attackers is to gain control over wallets by invading the infrastructure of cryptocurrency trading platforms and then illegally transferring large amounts of encrypted assets from these wallets.

SlowMist published a summary article revealing Lazarus Group's attack methods and analyzed their use of tactics such as social engineering, vulnerability exploitation, privilege escalation, internal network penetration and fund transfer etc.. At the same time based on actual cases they summarized defensive suggestions against APT attacks hoping to provide references for industry helping more organizations enhance security protection capabilities reducing potential threat impacts.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Trending news

More
1
Traders expect the Federal Reserve to cut interest rates twice by the end of 2025.
2
Whale address 0xc2a3 continues to increase its long positions in Bitcoin and Ethereum, bringing its total holdings to $158 million.

Crypto prices

More
Bitcoin
Bitcoin
BTC
$108,636.57
-1.73%
Ethereum
Ethereum
ETH
$3,935.91
-0.35%
Tether USDt
Tether USDt
USDT
$1
+0.01%
BNB
BNB
BNB
$1,152.1
-1.03%
XRP
XRP
XRP
$2.39
-1.52%
Solana
Solana
SOL
$190.48
-3.00%
USDC
USDC
USDC
$0.9998
-0.01%
TRON
TRON
TRX
$0.3202
+1.57%
Dogecoin
Dogecoin
DOGE
$0.1928
-2.33%
Cardano
Cardano
ADA
$0.6605
-1.12%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter