APT Group Targeting Cryptocurrency Industries — Debunked

2020-09-18 Uppsala Security

https://medium.com/sentinel-protocol/apt-group-targeting-cryptocurrency-industries-debunked-5f799028cfc1

Thumbnail for APT Group Targeting Cryptocurrency Industries — Debunked

Our findings show that APT group uses separate infrastructure for hosting phishing and C2 servers, which have links to DPRK based Lazarus APT group and CryptoCore APT group involved in compromising multiple cryptocurrency exchanges. The APT group uses spear phishing techniques via email to get a foothold on the victim machine that results in downloading multiple payloads from the phishing or C2 server to exfiltrate information. Phishing Infrastructure In order to understand the phishing infrastructure of the APT group, we gathered multiple bit[.]ly links used by the threat actor group and obtained the subsequent redirected phishing urls resolved by the bitly service and their resolved ip addresses shown in Fig 7. Based on the indicators of compromise (IOC’s) generated from our investigation, we found a number of matching IOC’s with 2 other research articles based on threat actor groups targeting cryptocurrency organizations using a similar modus operandi uncovered by us.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN digifincx.com 2020-06-24 2022-01-13
IPv4 66.181.166.15 2020-06-24 2021-05-24
IPv4 140.117.91.22 2020-06-24 2021-01-28
URL https://forum.mikrotik.com/view… 2020-09-18 2020-09-18
DOMAIN forum.mikrotik.com 2020-09-18 2020-09-18
DOMAIN digifinex.com 2020-09-18 2020-09-18
IPv4 128.201.64.194 2020-06-24 2020-09-18
IPv4 203.144.133.42 2020-05-06 2020-09-18

Related Actors

Related Reports

« Back