FBI links North Korean hackers to $308 million crypto heist

Share:

The North Korean hacker group ‘TraderTraitor’ stole $308 million worth of cryptocurrency in the attack on the Japanese exchange DMM Bitcoin in May.

In a short post, the FBI attributed the attack to the state-affiliated threat actor TraderTraitor, also tracked as Jade Sleet, UNC4899, and Slow Pisces.

The crypto heist occurred in May 2024 and forced the platform to restrict account registration, cryptocurrency withdrawals, and trading until the completion of the investigations.

Earlier this week, a report from blockchain intelligence firm Chainalysis attributed the attack to North Korean threat actors but did not share any specific details.

Attack chain

In a short announcement, the FBI says that TraderTraitor’s attack on DMM Bitcoin started in late March 2024, when one of the attackers pretended to be a legitimate recruiter on LinkedIn and approached an employee of Ginco, a Japanese enterprise cryptocurrency wallet software company.

The hacker sent the Ginco employee, who had access to his employer’s wallet management system, a job proposal involving a pre-employment test on GitHub. This tactic has been popular with North Korean threat groups this year [1, 2].

The victim received a piece of malicious Python code to copy to their personal GitHub page in order to carry out the conduct the test. The code, however, compromised the computer and allowed TraderTraitor to infiltrate Ginco and then move laterally to DMM.

“After mid-May 2024, TraderTraitor actors exploited session cookie information to impersonate the compromised employee and successfully gained access to Ginco’s unencrypted communications system,” explains the FBI.

“In late May 2024, the actors likely used this access to manipulate a legitimate transaction request by a DMM employee, resulting in the loss of 4,502.9 BTC, worth $308 million at the time of the attack,” the agency says.

U.S. authorities have been monitoring the activity of TraderTraitor since 2022 when the threat actor started to target the blockchain space with fake apps.

In 2023, GitHub warned of a social engineering campaign conducted by the particular threat actors on the platform, targeting the accounts of developers in the blockchain, cryptocurrency, online gambling, and cybersecurity sectors.

Later, the FBI warned that TraderTraitor was preparing to cash out 1,580 Bitcoin (valued at the time at around $41 million) stolen from various sources that year.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:48 pm, Jan 16, 2025
weather icon 8°C
L: 7° | H: 8°
clear sky
Humidity: 87 %
Pressure: 1035 mb
Wind: 6 mph WSW
Wind Gust: 9 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:58 am
Sunset: 4:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 8°°C 0 mm 0% 4 mph 87 % 1035 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 4 mph 83 % 1034 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 7 mph 88 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 7 mph 93 % 1021 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 8°°C 0 mm 0% 4 mph 87 % 1035 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 7°°C 0 mm 0% 3 mph 90 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 5°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 95 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 5 mph 77 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 3 mph 76 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,235.17
0.38%
Ethereum(ETH)
€3,241.38
-2.14%
XRP(XRP)
€3.29
14.29%
Tether(USDT)
€0.97
-0.03%
Solana(SOL)
€207.30
5.47%
Dogecoin(DOGE)
€0.375162
2.39%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
0.58%
Pepe(PEPE)
€0.000017
-0.93%
Peanut the Squirrel(PNUT)
€0.59
-3.49%
Scroll to Top