Cryptocurrency Exchanges, Students Targets of North Korea Hackers
ID: 09ad394f-9648-55b4-b2c0-6667bb67b664
STIX ID: report--09ad394f-9648-55b4-b2c0-6667bb67b664
Feed Name: Security Ledger
Threat Score
Late-2017 state-sponsored cyber campaign attributed to North Korea's Lazarus Group targeted South Korean cryptocurrency users, exchanges (including Coinlink), and college students via spear-phishing using malicious Hangul (.hwp) files that exploited a Ghostscript vulnerability (CVE-2017-8291); the malware reused Destover code and is linked to wider ransomware and cryptocurrency theft activity including connections to the WannaCry incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
