APT Group Targeting Cryptocurrency Industries — Debunked
2020-09-18 • Uppsala Security •
Our findings show that APT group uses separate infrastructure for hosting phishing and C2 servers, which have links to DPRK based Lazarus APT group and CryptoCore APT group involved in compromising multiple cryptocurrency exchanges. The APT group uses spear phishing techniques via email to get a foothold on the victim machine that results in downloading multiple payloads from the phishing or C2 server to exfiltrate information. Phishing Infrastructure In order to understand the phishing infrastructure of the APT group, we gathered multiple bit[.]ly links used by the threat actor group and obtained the subsequent redirected phishing urls resolved by the bitly service and their resolved ip addresses shown in Fig 7. Based on the indicators of compromise (IOC’s) generated from our investigation, we found a number of matching IOC’s with 2 other research articles based on threat actor groups targeting cryptocurrency organizations using a similar modus operandi uncovered by us.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | digifincx.com | 2020-06-24 | 2022-01-13 |
| IPv4 | 66.181.166.15 | 2020-06-24 | 2021-05-24 |
| IPv4 | 140.117.91.22 | 2020-06-24 | 2021-01-28 |
| URL | https://forum.mikrotik.com/view… | 2020-09-18 | 2020-09-18 |
| DOMAIN | forum.mikrotik.com | 2020-09-18 | 2020-09-18 |
| DOMAIN | digifinex.com | 2020-09-18 | 2020-09-18 |
| IPv4 | 128.201.64.194 | 2020-06-24 | 2020-09-18 |
| IPv4 | 203.144.133.42 | 2020-05-06 | 2020-09-18 |