New Malware Sheds Light on How Cryptocurrency Exchanges Get Hacked

New Malware Sheds Light on How Cryptocurrency Exchanges Get Hacked
фото показано с : beincrypto.com

2019-10-16 08:17

Ever wondered how cryptocurrency exchanges get hacked? Well, a new malware attempt by a North Korean hacking group might reveal some of what goes into such an attack.

The new malware operates under the guise of a client-side trading software called “JTM Trading Software” and appears to be operated by the infamous North Korean Lazarus APT Group. It is primarily distributed to unsuspecting victims over email.

In order to make the operation seem more authentic, those behind the malware even fabricated an entire company known as “Celas Trade Pro” and developed a convincing-looking website and GitHub profile to help quell suspicions surrounding the software.

An Older Trojan, Just Repurposed

After installing the base application, a script would then run to install a backdoor on the user’s system. This backdoor would be executed every time the computer is restarted, ensuring it is always operating in the background.

As for exactly what the backdoor does, it appears that it allows a remote attacker to execute hidden shell commands on the user’s system, which could allow the attacker to easily exfiltrate data to a remote server (IP: 185.228.83.32), snoop on the current state of the infected system and possibly install additional malware silently.

According to the report by Objective-See, the malware appears to be built on the code of a previously detected unnamed backdoor and is likely produced by the same North Korean malware team known as Lazarus.

“The ability to remotely execute commands, clearly gives a remote attacker full and extensible control over the infected macOS system!” notes security researcher Patrick Wardle (Objective-See).

What is particularly worrying about JTM Trading software is that up until just days ago, the malware was completely undetectable by most popular antiviruses, while according to VirusTotal, two-thirds of antiviruses still fail to recognize its malicious behavior.

macOS Users Under The Crosshair

The new attack is rare among exploits since it only targets devices running macOS—arguably one of the most secure operating systems in use today.

However, since Apple’s Gatekeeper software ensures that macOS users can only easily install apps from trusted vendors, or are required to manually confirm that they wish to open untrusted apps through a multi-step process that warns users against doing so every step of the way.

In order to avoid this issue, MacOS software providers will need to be part of the Apple Developer Program or Apple Developer Enterprise Program, which will allow them to develop a Developer ID certificate and sign their software with it, before submitting it for notarization by Apple. However, phony companies distributing virus-laden software will almost certainly fail to obtain a Developer IP certificate, which means any malware distributed to a target victim will need to be manually installed.

Like its predecessor, it appears the new malware is targeted at those with access to the back-end of cryptocurrency exchanges. After installation, the malware would likely be used for stealing private keys and access details, which could then be used to drain the exchange coffers.

As of yet, it is unclear whether anybody has been successfully fooled by the attack.

Speaking of which, recently, BeInCrypto reported on a cybersecurity firm that found some malware that utilizes Bitcoin script.

Do you think the same hacking group could be behind some of the recent exchange hacks? Let us know your thoughts in the comments below!

Images are courtesy of Shutterstock.

The post New Malware Sheds Light on How Cryptocurrency Exchanges Get Hacked appeared first on BeInCrypto.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Time New Bank (TNB) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.01 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.002809 (-100%)

new malware get hacked exchanges cryptocurrency north

new malware → Результатов: 126


Фото:

As Crypto ATMs Gain Popularity, Hackers Are Peddling Malware Targeting the Machines

Observant people living in major urban centers might have noticed by now a new type of ATM popping up. These are called cryptocurrency ATMs, and they do not need cards to operate. They are in place to cater to the need of some crypto holders who want to quickly exchange some of their digital coins […] As Crypto ATMs Gain Popularity, Hackers Are Peddling Malware Targeting the Machines was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-8-9 16:00


New Mining Malware threatens crypto-world – ZombieBoy

Earlier this week, the presence of a new crypto mining malware was discovered named ZombieBoy. This malware started mining initially at $1000 per month. The existence of this threat was revealed by a Private security researcher, James Quinn Tweet by Latest Hacking News: “ZombieBoy: New Crypto-Mining Malware Exploits Multiple CVEs” ZombieBoy was named after its use […]

2018-8-4 20:57


PowerGhost, the latest Cryptomining malware discovered by Kaspersky

Kaspersky researchers have recently discovered a new cryptojacking campaign named PowerGhost that aims at infecting corporate networks worldwide in order to generate maximum mining profits. Cryptomining malware refers to software programs and malware components that are developed to forcefully take over a computer’s resources and adopt them for cryptocurrency mining without a user’s approval. The cryptojacking […]

2018-7-29 04:55


Фото:

Kapersky Reports New Crypto Mining Malware Targeting Corporate Networks

Researchers at Kaspersky Lab have uncovered a new form of cryptojacking malware targeting corporations in multiple countries, the cybersecurity firm reported Thursday. PowerGhost, a form of fileless malware – which uses a system’s native processes to hijack a computer – has reportedly been spreading on corporate networks in India, Brazil, Colombia and Turkey. The miner

2018-7-27 22:38


Фото:

Report: 2.3 Million Bitcoin biodatas Focused on by Malware That ‘Hijacks’ Windows Clipboard

A new attack on Bitcoin users which gains control of Windows clipboard to swap out addresses is already monitoring 2.3 million targets, sources reported June 30. The malware, part of a family of threats known as “clipboard hijackers,” secretly gains control of memory, running in the background to ensure users do not notice its presence.

2018-7-2 20:18


Фото:

Cryptojacking Up 629% in Q1 2018, Says McAfee Report ‘Infect and Collect’

Cryptojacking malware activity rose a staggering 629 percent in the first quarter of 2018, according to a new report published by cyber security firm McAfee Labs June 27. Cryptojacking is the practice of using a computer’s processing power to mine for cryptocurrencies without the owner’s consent or knowledge. The McAfee Labs Threats Report for June

2018-6-29 16:27