logo

Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

ID: 55658cf9-b056-55b1-bb1e-4625d818163b

STIX ID: report--55658cf9-b056-55b1-bb1e-4625d818163b

Feed Name: Elastic Security Labs

Threat Score
92/100

Date Published: 2025-05-06

Date Updated: 2026-04-27

...
...

This Elastic research emulates a real-world supply-chain intrusion attributed to DPRK operators that compromised a Safe{Wallet} developer macOS host via a malicious Python application exploiting PyYAML deserialization, deployed a loader and Poseidon-based payloads to harvest AWS session tokens, pivoted to an S3-hosted Next.js frontend to inject JavaScript that redirected a ByBit multisig transaction, and resulted in the theft of ~400,000 ETH; the report includes detailed malware behavior, cloud attack chain, detections, and hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.