logo

Exclusive Look Inside a Compromised North Korean APT Machine Linked to The Biggest Heist in History

ID: a27df1ed-2b15-5242-9a2d-368d5a80e4cb

STIX ID: report--a27df1ed-2b15-5242-9a2d-368d5a80e4cb

Feed Name: infostealers.com

Threat Score
90/100

Date Published: 2025-12-03

Date Updated: 2026-06-07

Author: InfoStealers

...
...

**Executive summary:** Hudson Rock analyzed a LummaC2 infostealer log from a compromised machine belonging to a North Korean malware developer; stolen credentials (notably 'trevorgreer9312' and an email linked to bybit-assessment.com) and artifacts tie the host to the Lazarus/DPRK ecosystem and infrastructure used in the $1.4B ByBit heist, while installed tooling and domain/subdomain registrations indicate active development, packing/obfuscation, phishing infrastructure, and cloud-based exfiltration channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.