DEV-0139 launches targeted attacks against the cryptocurrency industry
2022-12-06 • Microsoft •
Microsoft investigated DEV-0139 activity targeting cryptocurrency investment companies through carefully prepared Telegram social engineering. The actor joined VIP cryptocurrency exchange communication groups, impersonated OKX-linked contacts, and moved employees into a secondary chat before sending a weaponized Excel file named OKX Binance & Huobi VIP fee comparision.xls. The macro used VBA UserForm obfuscation to drop VSDB688.tmp, retrieve a PNG from od.lk, and extract logagent.exe, a malicious wsock32.dll, and an XOR-encoded backdoor for DLL side-loading and remote access. Microsoft also connected the technique to a CryptoDashboardV2 MSI variant that side-loaded DUser.dll via TPLink.exe, indicating repeated use of DLL proxying against cryptocurrency-sector targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | strainservice.com | 2022-12-01 | 2023-10-26 |
| HASH | 8400f2674892cdfff27b0dfe98a2a77… | 2022-12-06 | 2022-12-06 |
| HASH | d021d412be456a6f78a0052a1f0e355… | 2022-12-06 | 2022-12-06 |
| URL | https://od.lk/d/d021d412be456a6… | 2022-12-06 | 2022-12-06 |
| IPv4 | 198.54.115.248 | 2022-12-06 | 2022-12-06 |
| HASH | e5980e18319027f0c28cd2f581e75e7… | 2022-12-01 | 2022-12-06 |
| HASH | a2d3c41e6812044573a939a51a22d65… | 2022-12-01 | 2022-12-06 |
| HASH | abca3253c003af67113f83df2242a70… | 2022-12-01 | 2022-12-06 |