Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#Coinis • 2017-09
Coinis was cited in reporting on Lazarus-linked cryptocurrency exchange intrusions after attackers allegedly stole a code-signing certificate in the Coinis/WaveString breach, signed malware disguised as an OpenSSL library, and pushed malicious files through the Coinis HTS update path. Kaspersky researchers tied the activity to a Lazarus fake software company and broader financially motivated operations against cryptocurrency traders and exchanges.
5
Related Reports
1
Affected Countries
105
Months Since
Lazarus Under The Hood