APT-C-26 (Lazarus)组织对数字货币交易所的最新攻击预警
2019-03-29 • Qihoo360 • APT-C-26 (Lazarus) group's latest attack warning on digital currency exchanges •
360 researchers linked APT-C-26, identified in the excerpt as Lazarus, to continued attacks against cryptocurrency exchanges and related users. The group allegedly registered wb-invest.net and wb-bot.org in October 2018, then used them to present a malicious automated trading application called Worldbit-bot as legitimate software. Worldbit-bot was described as modified from the open-source Qt Bitcoin Trader project and as using the same attack framework as the earlier CelasTrade Pro campaign, with changes mainly in parameters and keys. The reported phishing activity targeted exchange staff in suspected January and March 2019 operations to enable cryptocurrency theft, showing a mature and repeated tradecraft pattern against blockchain-sector victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | wb-bot.org | 2019-03-29 | 2020-01-08 |
| HASH | 3efeccfc6daf0bf99dcb36f247364052 | 2019-03-29 | 2020-01-08 |
| HASH | b63e8d4277b190e2e3f5236f07f89eee | 2019-03-29 | 2020-01-08 |
| HASH | 8b4c532f10603a8e199aa4281384764e | 2019-03-29 | 2020-01-08 |
| DOMAIN | wb-invest.net | 2019-03-29 | 2019-03-29 |