Security firm: Devices used by North Korean hackers involved in an exchange theft case were infected with the LummaC2 virus
According to ChainCatcher, citing a report from Hackread.com, cybersecurity firm Hudson Rock discovered, while analyzing a LummaC2 info-stealer malware log, a compromised device operated by a suspected malware developer from a North Korean state-sponsored hacker group.
This device was previously used to set up infrastructure supporting the $1.4 billion cryptocurrency exchange theft scheduled for February 2025. Analysis shows that credentials found on the device are linked to domains registered before the attack, which were used to impersonate the exchange. The device itself is high-end, equipped with development tools such as Visual Studio and Enigma Protector, as well as communication and data storage applications like Astrill VPN, Slack, and Telegram. Activity traces also indicate that the attacker purchased related domains and prepared a fake Zoom installer to carry out phishing attacks. This discovery unusually reveals internal operational details of asset sharing within North Korean-backed hacking campaigns.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Major progress made in the US-South Korea $350 billions investment agreement; the first project targets a $22.3 billions gas power plant in Texas
The long-standing investment agreement between the United States and South Korea has made "significant progress."
Proact launches share buyback program, caps holdings at 10% of outstanding shares
SBF swings to H1 FY26 profit of €0.6 million; EBITDA more than doubled to €1.6 million

Euro: De-escalation risk weighs on EUR against US Dollar – Commerzbank

