北 랜섬웨어 관련 비트코인 주소 트랜잭션 추적(1)

2023-04-04 Plainbit Tracking Bitcoin address transactions related to North Korean ransomware (1)

https://blog.plainbit.co.kr/cisa-northkorea-ransomware/

Plainbit summarizes a February 2023 CISA joint advisory on North Korea-linked ransomware and reviews 43 cryptocurrency addresses published as related indicators. The source says the advisory covers TTPs, IOCs, and cryptocurrency use by North Korean cyber actors targeting healthcare, public health, and other critical infrastructure for ransomware operations. Using QLUE, the author found transaction history for 9 of the 43 listed Bitcoin addresses and observed that all addresses with activity had sent out their balances by the review date. The report is useful for DPRK ransomware tracking because it establishes the wallet set for follow-on transaction analysis and flags possible data-quality issues, including two malformed or non-Bitcoin addresses.

Related Reports

« Back