Exclusive Look Inside a Compromised North Korean APT Machine Linked to The Biggest Heist in History
ID: a27df1ed-2b15-5242-9a2d-368d5a80e4cb
STIX ID: report--a27df1ed-2b15-5242-9a2d-368d5a80e4cb
Feed Name: infostealers.com
**Executive summary:** Hudson Rock analyzed a LummaC2 infostealer log from a compromised machine belonging to a North Korean malware developer; stolen credentials (notably 'trevorgreer9312' and an email linked to bybit-assessment.com) and artifacts tie the host to the Lazarus/DPRK ecosystem and infrastructure used in the $1.4B ByBit heist, while installed tooling and domain/subdomain registrations indicate active development, packing/obfuscation, phishing infrastructure, and cloud-based exfiltration channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
