Bitmex discovers that cyber security is in a group of hackers in North Korea

Published on:

The BitMex Crypto Exchange security team has discovered gaps in the field of operating security Lazarus Group, sponsored by the government of the cybercrime network in North Korea (DPRK), in accordance with the probe prevention of the organization, which revealed IP addresses, database and tracking algorithms used by the group’s plant.

Safety researchers say that there is a high probability that at least one hacker accidentally revealed his real IP address, which showed the actual location of the hacker in Jiaxing in China.

In addition, Bitmex researchers claim that they were also able to access the Suppabase database instance, platforms for basic implementation of databases with elementary application interfaces used by a hacking group.

The Bitmex safety team said that one of the hackers probably revealed its real IP address accidentally after he did not exploit VPN regularly used to mask the IP address. Source: Bitmex

According to reportThe analysis emphasized the asymmetry between social engineering teams in a group designed to guide nothing suspected victims to download malware and interaction with sophisticated code exploits developed by advanced technologies.

This asymmetry signals that the hacker organization associated with North Korea has divided into separate subgroups, with different levels of threat possibilities cooperating in order to deceive users, said Bitmex team.

Bitmex, North Korea, Cyber ​​security, Hacks, Lazarus Group
The number of recent malware infections caused by Lazarus hackers during the observation period. Source Bitmex

The report is a consequence of a number of raucous hacking incidents, social engineering fraud and infiltration of blockchain and companies related to the Lazarus Group and other agents related to North Korea.

Related: The northern Korean spy slips, reveals ties in a false interview

Federal law enforcement agencies and governments check the alarm in the Lazarus group

Federal law enforcement agencies and governments around the world are increasingly investigating the activities of hackers related to DPRK, sounding alarm in a number of common fraud strategies used by these threatening entities.

In September 2024, the Federal United States Investigative Bureau (FBI) issued a warning about the fraud of social engineering committed by the group supported by the DPRK, including phishing tests focused on cryptographic users with false employment offers.

https://www.youtube.com/watch?v=ndv0rfeetq

The governments of Japan, the USA and South Korea repeated the FBI warning in January 2025 and characterized the hacking activity as a threat to the financial system.

The recent Bloomberg report suggested that world leaders could discuss the threat of the Lazarus hacker group at the next G7 summit and strategies of damages caused by the organization related to the DPRK.

Warehouse: Lazarus’ favorite exploit was revealed – analysis of cryptographic hacks

Related

Leave a Reply

Please enter your comment!
Please enter your name here