Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

2025-05-06 Elastic

https://www.elastic.co/security-labs/bit-bybit

Thumbnail for Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

Supply chain targeting has become a hallmark of the DPRK’s cyber strategy, underpinning the regime’s theft of more than $6 billion in cryptocurrency since 2017. Initial access involved social engineering, likely approaching the developer via platforms like LinkedIn, Telegram, or Discord, based on previous campaigns, and convincing them to download an archive file containing a crypto-themed Python application—an initial access procedure favored by DPRK. DPRK continually targets these companies due to the relative anonymity and decentralized nature of cryptocurrency, enabling the regime to evade global financial sanctions. Unknown to the developer, this seemingly benign application enabled DPRK operators to exploit a remote code execution (RCE) vulnerability in the PyYAML library, providing code execution capabilities and subsequently control over the host system.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN getstockprice.com 2025-03-11 2025-12-10
HASH 937c533bddb8bbcd908b62f2bf48e5b… 2025-04-14 2025-05-06
HASH e89bf606fbed8f68127934758726bbb… 2025-04-14 2025-05-06
HASH 47e997b85ed3f51d2b1d37a6a61ae72… 2025-04-14 2025-05-06
URL https://app.safe.global/_next/s… 2025-02-27 2025-05-06
DOMAIN app.safe.global 2025-02-26 2025-05-06

Related Actors

Related Reports

« Back