Exclusive Look Inside a Compromised North Korean APT Machine Linked to The Biggest Heist in History

2025-12-03 Hudson Rock

https://www.hudsonrock.com/blog/5692

Thumbnail for Exclusive Look Inside a Compromised North Korean APT Machine Linked to The Biggest Heist in History

Hudson Rock analyzed a LummaC2 infostealer log from a machine it identifies as a high-level North Korean threat actor malware development rig. The stolen credentials included [email protected], which Silent Push linked to registration of bybit-assessment[.]com shortly before the $1.4 billion ByBit theft, connecting the machine to broader DPRK infrastructure associated with the heist. Artifacts on the host included Visual Studio Professional 2019, Enigma Protector v7.40, Astrill VPN usage through 104.223.97.2, Chinese-Simplified browser settings, Korean translation activity, cryptocurrency wallet and BitPay troubleshooting, and use of Dropbox, Slack, and Telegram. The report also describes domains such as callapp.us and callservice.us with Zoom-themed subdomains, suggesting phishing infrastructure designed to deliver malware through spoofed conferencing lures.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-25 2025-12-16
DOMAIN bybit-assessment.com 2025-02-25 2025-12-10
IPv4 104.223.97.2 2024-09-23 2025-12-03

Related Actors

Related Reports

« Back