logo

Cryptocurrency Exchanges, Students Targets of North Korea Hackers

ID: 09ad394f-9648-55b4-b2c0-6667bb67b664

STIX ID: report--09ad394f-9648-55b4-b2c0-6667bb67b664

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2018-01-16

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Late-2017 state-sponsored cyber campaign attributed to North Korea's Lazarus Group targeted South Korean cryptocurrency users, exchanges (including Coinlink), and college students via spear-phishing using malicious Hangul (.hwp) files that exploited a Ghostscript vulnerability (CVE-2017-8291); the malware reused Destover code and is linked to wider ransomware and cryptocurrency theft activity including connections to the WannaCry incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.