Bit ByBit - emulation of the DPRK's largest cryptocurrency heist
2025-05-06 • Elastic •
Supply chain targeting has become a hallmark of the DPRK’s cyber strategy, underpinning the regime’s theft of more than $6 billion in cryptocurrency since 2017. Initial access involved social engineering, likely approaching the developer via platforms like LinkedIn, Telegram, or Discord, based on previous campaigns, and convincing them to download an archive file containing a crypto-themed Python application—an initial access procedure favored by DPRK. DPRK continually targets these companies due to the relative anonymity and decentralized nature of cryptocurrency, enabling the regime to evade global financial sanctions. Unknown to the developer, this seemingly benign application enabled DPRK operators to exploit a remote code execution (RCE) vulnerability in the PyYAML library, providing code execution capabilities and subsequently control over the host system.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | getstockprice.com | 2025-03-11 | 2025-12-10 |
| HASH | 937c533bddb8bbcd908b62f2bf48e5b… | 2025-04-14 | 2025-05-06 |
| HASH | e89bf606fbed8f68127934758726bbb… | 2025-04-14 | 2025-05-06 |
| HASH | 47e997b85ed3f51d2b1d37a6a61ae72… | 2025-04-14 | 2025-05-06 |
| URL | https://app.safe.global/_next/s… | 2025-02-27 | 2025-05-06 |
| DOMAIN | app.safe.global | 2025-02-26 | 2025-05-06 |