Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#MGNR • 2021-10
MGNR disclosed that it was hit by a malicious and targeted cyberattack in which the likely entry point was a phishing email impersonating a recognized sender and carrying a fake document. The intrusion was believed to have installed a keylogger and stolen password-manager credentials for a temporary shared hot wallet private key, with the attackers showing scripting capability and facility with cross-chain bridging and mixing techniques; later blockchain analysis associated MGNR with a Lazarus/Bluenoroff-linked cryptocurrency laundering cluster.
3
Related Reports
1
Affected Countries
56
Months Since
Lazarus Under The Hood