New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

SnatchCrypto attack hits DeFi and Blockchain Platforms with backdoor

New York Tech Editorial Team by New York Tech Editorial Team
January 16, 2022
in Cybersecurity
0
SnatchCrypto attack hits DeFi and Blockchain Platforms with backdoor
Share on FacebookShare on Twitter

Kaspersky researchers believe that North Korean government-backed hackers from the Lazarus Group are behind the SnatchCrypto attack.

The IT security researchers at Kaspersky have revealed details of a new campaign that the company has been tracking under the name SnatchCrypto.

According to Kaspersky’s research, this campaign entails emptying cryptocurrency wallets of those organizations that are part of crypto and financial spaces. 

Countries targeted in SnatchCrypto attack

Research reveals that the campaign has been active since 2017 and its main targets are FinTech sector firms in the following countries:

  1. India
  2. China
  3. Poland
  4. Russia
  5. Ukraine
  6. Vietnam
  7. Slovenia
  8. Singapore
  9. Hong Kong
  10. United States
  11. Czech Republic
  12. United Arab Emirates

How the attack takes place

In a blog post, Kaspersky researchers explained how the attack works and how unsuspected users are tricked into giving away their funds.

“When the compromised user transfers funds to another account, the transaction is signed on the hardware wallet. However, given that the action was initiated by the user at the very right moment, the user doesn’t suspect anything fishy is going on and confirms the transaction on the secure device without paying attention to the transaction details.”

“The user doesn’t get too worried when the size of the payment he/she inputs is low and the mistake feels insignificant. However, the attackers modify not only the recipient address but also push the amount of currency to the limit, essentially draining the account in one move.”

BlueNoroff Responsible for the Campaign

Kaspersky researchers claim that the SnatchCrypto campaign is the work of an advanced persistent threat group known as BlueNoroff, which is suspected of having links with the North Korean hacking group Lazarus APT. 

Lazarus is tied to cyberattacks against the financial and banking sector and specializes in SWIFT-based intrusions in Bangladesh, Vietnam, and Taiwan. The group was branded as one of the leading threats to FinTech firms along with FIN7 and Cobalt Strike.

“The group seems to work more like a unit within a larger formation of Lazarus attackers, with the ability to tap into its vast resources: be it malware implants, exploits, or infrastructure,” Kaspersky researchers noted.

Reportedly, the group conducted a series of attacks against small and medium-sized firms that dealt in cryptocurrency, the blockchain, virtual assets, decentralized finance or DeFi, smart contracts, and FinTech.

This group builds and abuses trust to compromise company networks. It spends a lot of time getting to know its victims before launching the attack and has been studying cryptocurrency startups since November 2021. It also impersonates legit firms in phishing emails, including Emurgo, Coinsquad, Youbi Capital, and Sinovation Ventures.

“BlueNoroff compromises companies through precise identification of the necessary people and the topics they are discussing at a given time. A document sent from one colleague to another on a topic, which is currently being discussed, is unlikely to trigger any suspicion,” Kaspersky report read.

CVE-2017-0199

A remote code execution flaw tracked as CVE-2017-0199 is used to trigger a remote script linked to malicious files. The exploit fetches a payload from a URL embedded in those files. It also pulls a remote template. 

With these combined, a VBA macro and base64-encoded binary objects become available and are used to spawn a process for privilege escalation before executing the primary payload on a target system.

“Interestingly, BlueNoroff shows improved opsec at this stage. The VBA macro does a cleanup by removing the binary objects and the reference to the remote template from the original document and saving it to the same file. This essentially de-weaponizes the document leaving investigators scratching their head during analysis,” researchers explained.

It is worth noting that CVE-2017-0199 is being exploited since 2017. In August 2017, Palo Alto Networks Unit 42 discovered a phishing scam called FreeMilk that was hijacking active email conversations to deploy malware with the help of the same vulnerability.

In October 2017, Trend Micro found CVE-2017-0199 was exploited to use Windows Object Linking, and Embedding (OLE) flaw to spread malicious PowerPoint files by evading antivirus detection.

As for the ongoing attack, researchers observed additional infection chains, including zipped Windows shortcut files or malicious Word documents to fetch secondary-stage payloads. A PowerShell agent then deploys a backdoor.

Furthermore, the malware remotely connects to its operator’s C2 server, manipulates the registry and processes, executes commands, and steals data stored in the Chrome browser, WinSCP, and Putty. 

At this stage, attackers can also launch another backdoor, screenshot taker, and keylogger. The final payload used by BlueNoroff is a custom backdoor that collects system data and cryptocurrency software-related configuration and interjects between transactions carried out through hardware wallets.

More crypto and malware news on Hackread.com

The Pirate Bay malware can empty your Cryptocurrency wallet

Malware hits Hive OS cryptomining users; steals funds from wallets

Fake wallet update steals 1400 Bitcoin ($16 million) from Electrum user

Fake KPSPico Windows activator tool KPSPico steals crypto wallet data

Owner forgets the password to digital wallet with $240m of Bitcoin inside

 

Credit: Source link

Previous Post

Boulder Valley emerges as center for burgeoning robotics industry

Next Post

UAE’s Mubadala invests $100m in Israeli VC firms – report

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
UAE’s Mubadala invests $100m in Israeli VC firms – report

UAE's Mubadala invests $100m in Israeli VC firms - report

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media