I spent nearly 4 months investigating the inner workings of a North Korean state-sponsored hacking group. Here's what I found:
- The group used generative AI tools to aid in almost every part of their operations.
- They exfiltrated 26,584 cryptocurrency wallets from victim systems, with a combined value totaling as much $12 million dollars.
- In several cases, the threat actors set up entire front companies to lure in developers via fake job posting, then infected them with malware.
- The threat actors successfully pulled off a supply-chain attack by compromising a VS Code extension developer's system.
🔗 Full article: https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/