Uncovered: Lazarus Group's #APT38 uses Cosmic Rust malware to target macOS devices, linking back to known C&C servers. This highlights ongoing threats from North Korean hackers involved in global financial attacks. đŸ’»đŸ’„ #LazarusGroup #Korea https://www.hendryadrian.com/apt38-infrastructure-hunt-uncovers-macos-malware/
APT38 Infrastructure Hunt Uncovers macOS Malware

North Korean threat actor Lazarus Group and its financially motivated subgroup APT38 (Bluenoroff) have conducted extensive cyberattacks targeting financial institutions worldwide, including the notable 2016 Bangladesh Bank heist. The malware family Cosmic Rust, associated with APT38, targets macOS and communicates with known command and control servers, aiding threat hunting efforts using identified IPs and domains. #LazarusGroup #APT38 #CosmicRust

Cybersecurity News Everyday

BitoPro’s $11M crypto heist exposes a shocking vulnerability—state-sponsored hackers exploited a routine update to breach hot wallets. Could your digital assets be next? Dive into how this wake-up call is reshaping crypto security.

https://thedefendopsdiaries.com/bitopro-cyberattack-a-wake-up-call-for-cryptocurrency-security/

#bitopro
#cryptocurrencysecurity
#lazarusgroup
#cyberattack
#blockchainsecurity

some hot goss about Lazarus Group's money laundering activity from the PRC's contracted blockchain analysts (who are actually some of the best in the biz)

https://x.com/Bitrace_team/status/1935187982925123731

#moneylaundering #LazarusGroup #DPRK #Bybit #crypto #crime #infosec #cybersecurity #NorthKorea

Bitrace (@Bitrace_team) on X

A few additional interesting facts: 1. #Lazarus funds are flowing between VAOTC entities in various countries or regions. Our informant said that a Korean restaurant owner in Tokyo tried to sell hacker funds to them; 2. Some of the stolen funds flowed back to #Bybit through the

X (formerly Twitter)

The WannaCry 😭 ransomware attack in 2017 is a case study in cybersecurity history as one of the most devastating weaponized exploits orchestrated by a North Korean state-sponsored hacking group. Here is how it happened.

https://negativepid.blog/the-wannacry-ransomware-attack/

#wannaCry #cyberattacks #ransomware #cyberwarfare #caseStudies #cybersecurity #lazarusGroup #EthernalBlue

BitMEX Thwarts Lazarus Group Social Engineering Attack

A major cryptocurrency derivatives platform, BitMEX, recently foiled a social engineering attack attributed to the notorious Lazarus Group, a hacking

Blaze Trends
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams - Image: Shutterstock, ArtHead.
The U.S. government today imposed economic sanctions... https://krebsonsecurity.com/2025/05/u-s-sanctions-cloud-provider-funnull-as-top-source-of-pig-butchering-scams/ #starkindustriressolutionsltd #infrastructurelaundering #neer-do-wellnews #alittlesunshine #ivanneculiti #lazarusgroup #suncitygroup #yurineculiti #webfraud2.0 #zachedwards #silentpush #microsoft #funnull #amazon
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security

U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security

i feel like there must be some linguistic reason these Chinese organized crime crypto money laundering companies always use the word "guarantee" in their names.

* Elliptic report: https://www.elliptic.co/blog/xinbi-guarantee
* Wired article: https://www.wired.com/story/xinbi-guarantee-crypto-scam-hub/

Also worth noting that Jacob Silverman and James Block (Dirty Bubble Media) were reporting on some of these Colorado based crypto scam companies a year and a half ago: https://www.thenation.com/article/economy/rocky-mountain-lie/

#Xinbi #XinbiGuarantee #crypto #crime #moneylaundering #corruption #colorado #NorthKorea #DPRK #pigbutchering #scams #fraud #Elliptic #triads #Zhongteng #ZhongtengAccounting #Telegram #China #LazarusGroup

Xinbi: The $8 Billion Colorado-Incorporated Marketplace for Pig-Butchering Scammers and North Korean Hackers

Xinbi Guarantee is a Chinese-language, Telegram-based marketplace for cyber fraudsters in Southeast Asia, dealing primarily in the USDT stablecoin. With $8.4 billion in transactions since 2022, it offers tools and services for scams, including money laundering, fake IDs, and stolen data. The platform is linked to North Korean hackers and operates through a Colorado-incorporated entity.

good thing the US is gutting beneficial ownership regulations that would make it easier to understand who actually owns US trusts and corporations while simultaneously trashing both crypto enforcement at the DOJ but also more generally cyber defense

"The companies, Blocknovas LLC and Softglide LLC, were set up in the states of #NewMexico and New York using fake personas and addresses."

* Reuters: https://www.reuters.com/sustainability/boards-policy-regulation/north-korean-cyber-spies-created-us-firms-dupe-crypto-developers-2025-04-24/
* Technical details from Silent Push: https://www.silentpush.com/blog/contagious-interview-front-companies/

#DPRK #NorthKorea #hackers #crypto #cybersecurity #infosec #uspol #Nypol #newyork #uspolitics #contagiousInterview #Github #lazarusGroup

North Korean hackers set up fake U.S. companies to target cryptocurrency developers with malware, aiming to steal crypto wallets and credentials. Backed by the Lazarus Group, this attack highlights the growing sophistication of cyber espionage. The FBI has seized one of the domains, and experts warn of increasing cyber threats.

#CyberSecurity #NorthKorea #LazarusGroup #TECHi #CryptocurrencySecurity #CyberAttack

Read Full Article Here :- https://www.techi.com/north-korean-cyber-spies-caught-us-created-crypto-firms-disguise/

North Korean Cyber Spies Caught in the US, Created Crypto Firms to Disguise 

North Korea has once again made headlines for breaching US Treasury sanctions through an audacious cyber scheme. According to the US cybersecurity firm Silent

TECHi