北 랜섬웨어 관련 비트코인 주소 트랜잭션 추적(8)

2023-04-05 Plainbit Tracking Bitcoin address transactions related to North Korean ransomware (8)

https://blog.plainbit.co.kr/cisa-northkorea-ransomware-1kcwfcugnsy3pznx7u1i5nwfzrtth4brbc/

Plainbit traces CISA-listed North Korea ransomware address 1KCwfCUgnSy3pzNX7U1i5NwFzRtth4bRBc, a high-risk wallet in QLUE cluster 806944670 with ransomware and North Korea flags. The address handled six transactions totaling 0.0361 BTC between May 2021 and December 2022, with inputs associated with Coinbase activity and a peel-chain source. Outgoing flows connected to Binance, Hydra Market, Coinspaid-like infrastructure, and two addresses identified in the source as Lazarus Group-linked: 121AkmEbHBX9FuFeuDWv2CpyHqNq9F18k9 and 1C5qLPgqW4Ed6PuyLHPqXpdF2gQ1EEnJ65. The report highlights exchange use, peel-chain movement, and overlap with Lazarus-tagged wallets in North Korea ransomware fund tracing.

Related Reports

« Back