Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
North Korean hackers target crypto firms with new malware

North Korean hackers target crypto firms with new malware

GrafaGrafa2024/11/09 00:37
By:Isaac Francis

North Korean state-sponsored hackers have launched a new campaign, named ‘Hidden Risk,’ that targets crypto firms using malware disguised as legitimate documents, according to a report by SentinelLabs.

This campaign is linked to BlueNoroff, a subgroup of the notorious Lazarus Group, which has been known for stealing significant funds to support North Korea’s nuclear and weapons programs.

Unlike previous strategies that involved grooming victims on social media, this campaign focuses on phishing emails.

The emails are crafted to appear as crypto news alerts, tempting recipients to click on links that supposedly lead to genuine PDF documents.

Instead, users unknowingly download malware onto their macOS systems.

The report highlights that these phishing emails began surfacing in July and often included updates related to Bitcoin prices or trends in decentralised finance (DeFi).

This shift in tactics indicates an evolving approach by cybercriminals to infiltrate financial platforms and crypto exchanges.

The malware is particularly alarming due to its ability to bypass Apple’s built-in security features.

The software is signed with legitimate Apple Developer IDs, allowing it to evade macOS’s Gatekeeper system.

Once installed, the malware hides in system files, remaining undetected even after reboots, and communicates with servers controlled by the hackers.

This campaign aligns with warnings issued by the FBI about North Korean cyber actors increasingly targeting employees at DeFi and ETF firms using tailored social engineering attacks.

SentinelLabs has advised macOS users, especially those within organisations, to enhance their security protocols and remain vigilant against potential threats.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

WLFIUSDT now launched for pre-market futures trading

Bitget Announcement2025/08/23 13:50

New spot margin trading pair — SAPIEN/USDT!

Bitget Announcement2025/08/22 10:56

Bitget Will Delist MKR on 2025-08-22

Bitget Announcement2025/08/22 10:15