• bitcoinBitcoin (BTC) $ 98,317.00
  • ethereumEthereum (ETH) $ 3,448.46
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.31
  • bnbBNB (BNB) $ 678.30
  • solanaSolana (SOL) $ 193.40
  • dogecoinDogecoin (DOGE) $ 0.336109
  • usd-coinUSDC (USDC) $ 1.00
  • cardanoCardano (ADA) $ 0.960324
  • staked-etherLido Staked Ether (STETH) $ 3,442.18
  • tronTRON (TRX) $ 0.251565
  • avalanche-2Avalanche (AVAX) $ 40.60
  • chainlinkChainlink (LINK) $ 23.87
  • wrapped-stethWrapped stETH (WSTETH) $ 4,096.29
  • the-open-networkToncoin (TON) $ 5.51
  • suiSui (SUI) $ 4.76
  • shiba-inuShiba Inu (SHIB) $ 0.000023
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 97,947.00
  • polkadotPolkadot (DOT) $ 7.46
  • stellarStellar (XLM) $ 0.376764
  • hyperliquidHyperliquid (HYPE) $ 33.54
  • hedera-hashgraphHedera (HBAR) $ 0.268994
  • wethWETH (WETH) $ 3,446.97
  • bitcoin-cashBitcoin Cash (BCH) $ 468.37
  • leo-tokenLEO Token (LEO) $ 9.29
  • uniswapUniswap (UNI) $ 13.95
  • pepePepe (PEPE) $ 0.000019
  • litecoinLitecoin (LTC) $ 104.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,640.74
  • nearNEAR Protocol (NEAR) $ 5.40
  • bitget-tokenBitget Token (BGB) $ 4.35
  • ethena-usdeEthena USDe (USDE) $ 0.999964
  • aptosAptos (APT) $ 10.60
  • internet-computerInternet Computer (ICP) $ 10.93
  • usdsUSDS (USDS) $ 1.00
  • aaveAave (AAVE) $ 321.95
  • crypto-com-chainCronos (CRO) $ 0.167774
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.503467
  • ethereum-classicEthereum Classic (ETC) $ 27.45
  • mantleMantle (MNT) $ 1.22
  • render-tokenRender (RENDER) $ 7.64
  • vechainVeChain (VET) $ 0.048632
  • mantra-daoMANTRA (OM) $ 3.92
  • bittensorBittensor (TAO) $ 486.19
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.36
  • whitebitWhiteBIT Coin (WBT) $ 24.56
  • moneroMonero (XMR) $ 192.23
  • ethenaEthena (ENA) $ 1.18
  • daiDai (DAI) $ 1.00
  • arbitrumArbitrum (ARB) $ 0.805089
  • filecoinFilecoin (FIL) $ 5.25
  • kaspaKaspa (KAS) $ 0.125555
  • fantomFantom (FTM) $ 1.07
  • algorandAlgorand (ALGO) $ 0.355740
  • okbOKB (OKB) $ 46.22
  • cosmosCosmos Hub (ATOM) $ 7.04
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.69
  • blockstackStacks (STX) $ 1.79
  • ondo-financeOndo (ONDO) $ 1.82
  • optimismOptimism (OP) $ 1.90
  • bonkBonk (BONK) $ 0.000033
  • immutable-xImmutable (IMX) $ 1.46
  • celestiaCelestia (TIA) $ 5.38
  • movementMovement (MOVE) $ 1.03
  • theta-tokenTheta Network (THETA) $ 2.28
  • injective-protocolInjective (INJ) $ 22.31
  • dogwifcoindogwifhat (WIF) $ 2.16
  • the-graphThe Graph (GRT) $ 0.223694
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,447.17
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 98,306.00
  • sei-networkSei (SEI) $ 0.456728
  • worldcoin-wldWorldcoin (WLD) $ 2.37
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030152
  • thorchainTHORChain (RUNE) $ 5.35
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,575.31
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,864.14
  • flokiFLOKI (FLOKI) $ 0.000180
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • jasmycoinJasmyCoin (JASMY) $ 0.035741
  • gatechain-tokenGate (GT) $ 13.25
  • galaGALA (GALA) $ 0.038615
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,628.46
  • lido-daoLido DAO (LDO) $ 1.78
  • flare-networksFlare (FLR) $ 0.028267
  • tokenize-xchangeTokenize Xchange (TKX) $ 18.96
  • beam-2Beam (BEAM) $ 0.028829
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 98,358.00
  • makerMaker (MKR) $ 1,676.32
  • the-sandboxThe Sandbox (SAND) $ 0.598545
  • fasttokenFasttoken (FTN) $ 3.33
  • pyth-networkPyth Network (PYTH) $ 0.391628
  • usual-usdUsual USD (USD0) $ 1.00
  • tezosTezos (XTZ) $ 1.36
  • nexoNEXO (NEXO) $ 1.38
  • kaiaKaia (KAIA) $ 0.235039
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 98,154.00
  • based-brettBrett (BRETT) $ 0.137969
  • kucoin-sharesKuCoin (KCS) $ 11.32
  • raydiumRaydium (RAY) $ 4.63
  • eosEOS (EOS) $ 0.858389
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,544.12
  • heliumHelium (HNT) $ 7.12
  • binance-staked-solBinance Staked SOL (BNSOL) $ 197.50
  • ethereum-name-serviceEthereum Name Service (ENS) $ 37.10
  • jupiter-exchange-solanaJupiter (JUP) $ 0.886064
  • aerodrome-financeAerodrome Finance (AERO) $ 1.65
  • flowFlow (FLOW) $ 0.754368
  • xdce-crowd-saleXDC Network (XDC) $ 0.078167
  • starknetStarknet (STRK) $ 0.503550
  • arweaveArweave (AR) $ 17.29
  • iotaIOTA (IOTA) $ 0.315668
  • bitcoin-svBitcoin SV (BSV) $ 56.25
  • dydx-chaindYdX (DYDX) $ 1.57
  • aioz-networkAIOZ Network (AIOZ) $ 0.970331
  • curve-dao-tokenCurve DAO (CRV) $ 0.872608
  • bittorrentBitTorrent (BTT) $ 0.000001
  • coredaoorgCore (CORE) $ 1.15
  • msolMarinade Staked SOL (MSOL) $ 239.89
  • neoNEO (NEO) $ 14.83
  • axie-infinityAxie Infinity (AXS) $ 6.60
  • elrond-erd-2MultiversX (EGLD) $ 36.83
  • matic-networkPolygon (MATIC) $ 0.503807
  • decentralandDecentraland (MANA) $ 0.505238
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,456.56
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 97,370.00
  • apecoinApeCoin (APE) $ 1.23
  • pendlePendle (PENDLE) $ 5.37
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 97,759.00
  • fartcoinFartcoin (FARTCOIN) $ 0.877424
  • zcashZcash (ZEC) $ 54.16
  • mog-coinMog Coin (MOG) $ 0.000002
  • eigenlayerEigenlayer (EIGEN) $ 4.04
  • jito-governance-tokenJito (JTO) $ 3.12
  • chilizChiliz (CHZ) $ 0.090762
  • akash-networkAkash Network (AKT) $ 3.36
  • conflux-tokenConflux (CFX) $ 0.168883
  • wormholeWormhole (W) $ 0.287337
  • popcatPopcat (POPCAT) $ 0.811607
  • ai16zai16z (AI16Z) $ 0.714683
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,448.51
  • mina-protocolMina Protocol (MINA) $ 0.646560
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 205.43
  • compound-governance-tokenCompound (COMP) $ 85.30
  • usddUSDD (USDD) $ 0.998743
  • roninRonin (RON) $ 1.99
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.51
  • superfarmSuperVerse (SUPER) $ 1.64
  • spx6900SPX6900 (SPX) $ 0.794327
  • havvenSynthetix Network (SNX) $ 2.15
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,449.39
  • ecasheCash (XEC) $ 0.000037
  • chiaChia (XCH) $ 22.34
  • dydxdYdX (ETHDYDX) $ 1.57
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.007015
  • amp-tokenAmp (AMP) $ 0.008289
  • gnosisGnosis (GNO) $ 269.06
  • zksyncZKsync (ZK) $ 0.188284
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.335534
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.687211
  • notcoinNotcoin (NOT) $ 0.006708
  • axelarAxelar (AXL) $ 0.782350
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 97,489.00
  • chex-tokenCHEX Token (CHEX) $ 0.665588
  • layerzeroLayerZero (ZRO) $ 5.94
  • tether-goldTether Gold (XAUT) $ 2,634.33
  • fraxFrax (FRAX) $ 0.998619
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,628.11
  • reserve-rights-tokenReserve Rights (RSR) $ 0.011756
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000114
  • vanaVana (VANA) $ 19.77
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,730.36
  • grassGrass (GRASS) $ 2.55
  • turboTurbo (TURBO) $ 0.008836
  • oasis-networkOasis (ROSE) $ 0.086797
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006564
  • ordinalsORDI (ORDI) $ 27.77
  • usualUsual (USUAL) $ 1.25
  • blurBlur (BLUR) $ 0.278568
  • super-oethSuper OETH (SUPEROETHB) $ 3,449.69
  • safeSafe (SAFE) $ 1.12
  • 1inch1inch (1INCH) $ 0.408416
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.36
  • echelon-primeEchelon Prime (PRIME) $ 11.09
  • creditcoin-2Creditcoin (CTC) $ 1.38
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.559956
  • beldexBeldex (BDX) $ 0.077606
  • livepeerLivepeer (LPT) $ 14.58
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 98,213.00
  • susdssUSDS (SUSDS) $ 1.02
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • gigachad-2Gigachad (GIGA) $ 0.054652
  • pax-goldPAX Gold (PAXG) $ 2,631.50
  • apenftAPENFT (NFT) $ 0.00000053
  • kusamaKusama (KSM) $ 32.82
  • arkhamArkham (ARKM) $ 1.56
  • nervos-networkNervos Network (CKB) $ 0.011426
  • pumpbtcpumpBTC (PUMPBTC) $ 97,458.00
  • frax-etherFrax Ether (FRXETH) $ 3,446.56
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,444.64

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

0 171

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

  cointelegraph.com  + 1 more 8 h

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

Lazarus Group used a new form of malware in an attempt to compromise a crypto exchange, according to an October 31 report from Elastic Security Labs.

Elastic has named the new malware “KANDYKORN” and the loader program that loads it into memory “SUGARLOAD,” as the loader file has a novel “.sld” extension in its name. Elastic did not name the exchange that was targeted.

Crypto exchanges have suffered a rash of private-key hacks in 2023, most of which have been traced to the North Korean cybercrime enterprise, Lazarus Group.

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

KANDYKORN infection process. Source: Elastic Security Labs.

According to Elastic, the attack began when Lazarus members posed as blockchain engineers and targeted engineers from the unnamed crypto exchange. The attackers made contact on Discord, claiming they had designed a profitable arbitrage bot that could profit from discrepancies between prices of cryptos on different exchanges.

The attackers convinced the engineers to download this “bot.” The files in the program’s ZIP folder had disguised names like “config.py” and “pricetable.py” that made it appear to be an arbitrage bot.

Once the engineers ran the program, it executed a “Main.py” file that ran some ordinary programs as well as a malicious file called “Watcher.py.” Watcher.py established a connection to a remote Google Drive account and began downloading content from it to another file named testSpeed.py. The malicious program then ran testSpeed.py a single time before deleting it in order to cover its tracks.

During the single-time execution of testSpeed.py, the program downloaded more content and eventually executed a file that Elastic calls “SUGARLOADER.” This file was obfuscated using a “binary packer,” Elastic stated, allowing it to bypass most malware detection programs. However, they were able to discover it by forcing the program to stop after its initialization functions had been called, then snapshotting the process’ virtual memory.

According to Elastic, they ran VirusTotal malware detection on SUGARLOADER, and the detector declared that the file was not malicious.

Once SUGARLOADER was downloaded into the computer, it connected to a remote server and downloaded KANDYKORN directly into the device’s memory. KANDYKORN contains numerous functions that can be used by the remote server to perform various malicious activities. For example, the command “0xD3” can be used to list the contents of a directory on the victim’s computer, and “resp_file_down” can be used to transfer any of the victim’s files to the attacker’s computer.

Elastic believes that the attack occurred in April, 2023. It claims that the program is probably still being used to perform attacks today, stating:

“This threat is still active and the tools and techniques are being continuously developed.”

Centralized crypto exchanges and apps suffered a rash of attacks in 2023. Alphapo, CoinsPaid, Atomic Wallet, Coinex, Stake and others have been victims of these attacks, most of which seem to have involved the attacker stealing a private key off the victim’s device and using it to transfer customers’ cryptocurrency to the attacker’s address.

The US Federal Bureau of Investigation (FBI) has accused the Lazarus Group of being behind the Coinex hack, as well as performing the Stake attack and others.

Source

Leave A Reply

Your email address will not be published.