The North Korean hacker group UNC4899 attacked the trading platform, resulting in 9 users losing 14 million dollars, which has been compensated.

robot
Abstract generation in progress

[Coin World] It was reported that a certain trading platform experienced a complex security incident on July 24, resulting in 14 million dollars being stolen from 9 user accounts. There is evidence suggesting that this attack was initiated by UNC4899, a cyber espionage organization funded by the North Korean government, which colludes with the North Korean Reconnaissance General Bureau, publicly known as Lazarus Group, TraderTraitor, and Jade Sleet. The attack began with a social engineering attack targeting the development team, where the attacker seemed to launch the attack through a legitimate Open Source collaboration request. A team member was invited on an open-source software forum to help debug a development tool. After a brief discussion, the developer downloaded the file on a mobile device and then opened it using a company-issued MacBook. Before opening the file, researchers conducted malware detection on it, but the scan results were negative. After the program ran, it downloaded a hidden backdoor similar to common backend processes. This allowed the attacker to maintain access to the development environment and find an opportunity to change the database after a period of time, thereby gaining access to 9 accounts that had initiated withdrawal operations. Unauthorized withdrawal operations were detected two hours later and were immediately stopped, with all affected users receiving full compensation from the platform's treasury.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
ProposalDetectivevip
· 20h ago
Security protection is very important.
View OriginalReply0
ClassicDumpstervip
· 08-20 19:30
suckers play people for suckers and continue to rise
View OriginalReply0
RugpullSurvivorvip
· 08-20 08:30
Social engineering attacks are really harsh.
View OriginalReply0
DancingCandlesvip
· 08-20 08:28
Damn social engineering attack
View OriginalReply0
SigmaBrainvip
· 08-20 08:27
The rookie is too careless.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)