BitMEX successfully blocked a suspected Lazarus attack and discovered its IP address and major security omissions
BitMEX said in an announcement on Friday that its security team successfully blocked a social engineering attack launched by the Lazarus Group, a hacking group linked to North Korea, the Internet reported. BitMEX said: "Recently, an employee was contacted through LinkedIn and offered to collaborate on the development of the NFT Marketplace Web3 project with the purpose of inducing victims to run project code containing malicious code on their computers." The employee promptly identified the risk and reported it, and the security team intervened to investigate and found that the attack attempted to reuse malicious code called "BeaverTail". BitMEX pointed out: "We found that an 'operational security error' in the script may have exposed the attacker's 'original IP address'." The team also said: "The organization appears to have split into multiple groups with varying technical levels." They have identified at least 10 accounts that may be used to test or develop malware. BitMEX added: "This survey shows a sharp contrast between the organization's primary phishing strategies and its advanced utilization techniques."
Disclaimer: The views in this article are from the original Creator and do not represent the views or position of Hawk Insight. The content of the article is for reference, communication and learning only, and does not constitute investment advice. If it involves copyright issues, please contact us for deletion.