SlowMist: Investigation of North Korean APT’s Large-Scale Phishing Attack on NFT Users

2022-12-24 Slowmist

https://slowmist.medium.com/slowmist-our-in-depth-investigation-of-north-korean-apts-large-scale-phishing-attack-on-nft-users-362117600519

Thumbnail for SlowMist: Investigation of North Korean APT’s Large-Scale Phishing Attack on NFT Users

SlowMist investigated a large phishing campaign attributed to North Korean APT activity against cryptocurrency and NFT users. The campaign used hundreds of phishing domains, including 196 domains initially shared by PhantomXSec, to impersonate dozens of ETH and SOL projects and lure users into NFT-theft schemes. SlowMist linked the activity to broader wallet-draining infrastructure and described how attackers used fake project pages, malicious mint or claim flows, and domain clusters to steal assets from users in the crypto ecosystem. The report is useful for tracking DPRK-linked phishing infrastructure targeting NFT communities and Web3 users.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://tothesky.in 2022-12-24 2022-12-24
URL https://thedoodles.site 2022-12-24 2022-12-24
URL https://commonj.xyz 2022-12-24 2022-12-24
DOMAIN commonj.xyz 2022-12-24 2022-12-24
DOMAIN thedoodles.site 2022-12-24 2022-12-24
DOMAIN nserva.live 2022-12-24 2022-12-24
DOMAIN tothesky.in 2022-12-24 2022-12-24

Related Reports

« Back