Bitcoin is silver, compromise is gold: Emerging North Korea-based threat actors on the hunt for cryptocurrency
2021-09-08 • PWC •
https://www.youtube.com/watch?v=BOZecjABjSk&list=PLnKL6-WWWE_UkE-u0E0z148a66WQIEFFo&index=6
This presentation focuses on North Korea-based threat actors pursuing cryptocurrency and related financial targets as part of a broader pattern of revenue-driven operations. PwC highlights Black Alicanto, also known as DangerousPassword, CryptoCore, CryptoMimic, or LeeryTurtle, and the less publicly documented Black Dev 2 campaign called Operation Gold Hunting. The source says the talk examines spearphishing themes, malicious documents, infrastructure, and TTPs used against cryptocurrency wallets, venture-capital firms, and investment organizations worldwide. It also connects these activity clusters back to Lazarus Group/Black Artemis, making the session relevant for tracking DPRK-linked crypto theft tradecraft and infrastructure fingerprinting.