北 랜섬웨어 관련 비트코인 주소 트랜잭션 추적(2)
2023-04-04 • Plainbit • Tracking Bitcoin address transactions related to North Korean ransomware (2) •
https://blog.plainbit.co.kr/cisa-northkorea-ransomware-bc1q8xyt4jxhw7mgqpwd6qfdjyxgvjeuz57jxrvgk9/
Plainbit traces the CISA-listed North Korea ransomware address bc1q8xyt4jxhw7mgqpwd6qfdjyxgvjeuz57jxrvgk9, which QLUE flagged as Ransomware and North Korea with a high-risk score. The address received and sent 0.51256 BTC in two transactions during May-July 2022, with funds ultimately going to a NairaEx exchange address and related flows touching suspected exchange-linked wallets. The author assessed the upstream address as likely attacker-controlled rather than a direct victim wallet, then followed outputs to Coinspaid, MEXC, KuCoin, OKX, Binance, BigONE, and renBTC conversion. The source highlights laundering behavior relevant to DPRK ransomware finance tracking, including exchange off-ramps and chain-hopping through renBTC.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://nairaex.com/ | 2023-04-04 | 2023-04-04 |
| DOMAIN | nairaex.com | 2023-04-04 | 2023-04-04 |