CryptoCore Threat Actor (Lazarus Group) Targeting Cryptocurrency Exchanges
released on 2020-06-24 @ 03:21:51 PM
CryptoCore is an attack campaign against crypto-exchange companies that has been ongoing for three years and was discovered by ClearSky researchers. This cybercrime campaign is focused mainly on the theft of cryptocurrency wallets, and ClearSky estimates that the attackers have already made hundreds
of millions of dollars. The campaign is also known as CryptoMimic, Dangerous Password, and Leery Turtle. ClearSky's report attributes this campaign to North Korea's Lazarus APT Group. This attribution is a result of two stages of research and ClearSky assesses with a MEDIUM-HIGH likelihood that Lazarus group has been attacking crypto exchanges all over the world and in Israel for at least three years