Software supply-chain attacks, in which hackers corrupt widely used applications to push their own code to thousands or even millions of machines, have become a scourge, both insidious and potentially huge in the breadth of their impact. But the latest major software supply-chain attack, in which hackers who appear to be working on behalf of the North Korean government hid their code in the installer for a common VoIP application known as 3CX, seems so far to have had a prosaic goal: breaking into a handful of cryptocurrency companies.
Researchers at Russian cybersecurity firm Kaspersky today revealed that they identified a small number of cryptocurrency-focused firms as at least some of the victims of the 3CX software supply-chain attack that's unfolded over the past week. Kaspersky declined to name any of those victim companies, but it notes that they're based in western Asia.
Security firms CrowdStrike and SentinelOne last week pinned the operation on North Korean hackers, who compromised 3CX installer software that's used by 600,000 organizations worldwide, according to the vendor. Despite the potentially massive breadth of that attack, which SentinelOne dubbed Smooth Operator, Kaspersky has now found that the hackers combed through the victims infected with its corrupted software to ultimately target fewer than 10 machinesat least as far as Kaspersky could observe so farand that they seemed to be focusing on cryptocurrency firms with surgical precision.
View more
This was all just to compromise a small group of companies, maybe not just in cryptocurrency, but what we see is that one of the interests of the attackers is cryptocurrency companies, says Georgy Kucherin, a researcher on Kaspersky's GReAT team of security analysts. Cryptocurrency companies should be especially concerned about this attack because they are the likely targets, and they should scan their systems for further compromise.
Kaspersky based that conclusion on the discovery that, in some cases, the 3CX supply-chain hackers used their attack to ultimately plant a versatile backdoor program known as Gopuram on victim machines, which the researchers describe as the final payload in the attack chain. Kaspersky says the appearance of that malware also represents a North Korean fingerprint: It has seen Gopuram used before on the same network as another piece of malware, known as AppleJeus, linked to North Korean hackers. It's also previously seen Gopuram connect to the same command-and-control infrastructure as AppleJeus, and has seen Gopuram used previously to target cryptocurrency firms. All of that suggests not only that the 3CX attack was carried out by North Korean hackers, but that it may have been intended to breach cryptocurrency firms in order to steal from those companies, a common tactic of North Korean hackers ordered to raise money for the regime of Kim Jong-Un.
It has become a recurring theme for sophisticated state-sponsored hackers to exploit software supply chains to access the networks of thousands of organizations, only to winnow their focus down to a few victims. In 2020's notorious Solar Winds spy campaign, for instance, Russian hackers compromised the IT monitoring software Orion to push malicious updates to about 18,000 victims, but they appear to have stolen data from only a few dozen of them. In the earlier supply chain compromise of the CCleaner software, the Chinese hacker group known as Barium or WickedPanda compromised as many as 700,000 PCs, but similarly chose to target a relatively short list of tech firms.
This is becoming very common, says Kucherin, who also worked on the SolarWinds analysis and found clues linking that supply-chain attack to a known Russian group. During supply-chain attacks, the threat actor conducts reconnaissance on the victims, collecting information, then they filter out this information, selecting victims to deploy a second-stage malware. That filtering process is designed to help the hackers avoid detection, Kucherin points out, since deploying the second-stage malware to too many victims allows the attack to be more easily detected.
But Kucherin notes that the 3CX supply-chain attack was nonetheless detected relatively quickly, compared to others. The installation of the initial malware that the hackers appeared to use for reconnaissance was detected by companies like CrowdStrike and SentinelOne last week, less than a month after it was deployed. They tried to be stealthy, but they failed, Kucherin says. Their first-stage implants were discovered.
Given that detection, it's not clear how successful the campaign has been. Kucherin says Kaspersky hasn't seen any evidence of actual theft of cryptocurrency from the companies it saw targeted with the Gopuram malware.
But given the hundreds of thousands of potential victims of the 3CX supply-chain compromise, no one should conclude yet that crypto companies alone were targeted, says Tom Hegel, a security researcher with SentinelOne. The current theory at this point is that the attackers did initially target crypto firms to get into those high-value organizations, Hegel says. Im going to guess that once they saw the success of this, and the kinds of networks they were in, other objectives probably came into play.
For now, Hegel says, no single security firm can see the whole shape of the 3CX hacking campaign or definitively state its goals. But if North Korean hackers really did compromise a piece of software used by 600,000 organizations around the world and use it just to try to steal cryptocurrency from a handful of them, they may have thrown away the keys to a much larger kingdom.
This is all unfolding very quickly. I think well continue to gain better insight into the victims, Hegel says. But from an attacker standpoint, if all they did was target crypto firms, this was a dramatic wasted opportunity.
View post:
Massive 3CX Supply-Chain Hack Targeted Cryptocurrency Firms - WIRED
- Bitcoin Center NYC To Support Wednesday's CryptoCurrency Convention By Hosting After-Party [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- CryptoCurrency.org [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Qoinpro Cryptocurrency Faucet - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Global Issues Cryptocurrency Project - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- cryptocurrency - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- PotCoin @ Cryptocurrency convention NYC, Good Audio - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 2014 - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Unobtanium Cryptocurrency Explained - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- How To Create Your Own Cryptocurrency Co.Labs code ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- CryptoCoinsNews - Cryptocurrency and Bitcoin News with ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Joe Rogan and Reddit Co-founder Alexis Ohanian talk Dogecoin, Cryptocurrency - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- How To Assess A CryptoCurrency: AltCoin Assessment Protocol. What's the next big AltCoin? - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Reggie Middleton's UltraCoin @ NYC CryptoCurrency Convention - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- The future is Nxt (cryptocurrency platform) - Video [Last Updated On: April 19th, 2014] [Originally Added On: April 19th, 2014]
- CryptoCurrency Convention 4/9/14 - Dan Larimer Bitshares - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- CryptoCurrency Convention 4/9/14 - Xavier Hawk Permacredits - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Does a cryptocurrency have the potential to revolutionize Ukraine? - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Marscoin @ CryptoCurrency Convention NYC 4/9/14 - Lennart Lopin - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Vertcoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fisher - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- UltraCoin @ CryptoCurrency Convention NYC 4/9/14 - Reggie Middleton - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- iCoin @ CryptoCurrency Convention NYC 4/9/14 - Ryan Ridgeway - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- The Future of Cryptocurrency, Investing, and Crowdfunding (Toronto #BitcoinExpo Highlights) #548 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- mTrader.org - Cryptocurrency Mining System - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Know How 74 Cryptocurrency - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- CryptoCurrency of the World Unite! - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Bitpagar Cryptocurrency - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- Violincoin - The first cryptocurrency for musician - - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency: Get Mining! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- The Cryptocurrency Store - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- Bitcoin Song - The Cryptocurrency Store - Video [Last Updated On: May 25th, 2014] [Originally Added On: May 25th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Sudbury Cryptocurrency Conference, May 26th: Ethereum - Video [Last Updated On: May 30th, 2014] [Originally Added On: May 30th, 2014]
- 2014 Cubieboard 1, 2 - Mining Peercoins (SHA-256 based) Cryptocurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- 2nd Salaries in CryptoCurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- The Best Cryptocurrency Trading Platform - Video [Last Updated On: June 3rd, 2014] [Originally Added On: June 3rd, 2014]
- Cryptocurrency business forum - Video [Last Updated On: June 4th, 2014] [Originally Added On: June 4th, 2014]
- Cryptocurrency Opportunities in Southeast Asia | John KIM - Video [Last Updated On: June 7th, 2014] [Originally Added On: June 7th, 2014]
- Facebook Approves Cryptocurrency Tipping Apps -- Bitcoin Weekend In San Francisco - Video [Last Updated On: June 8th, 2014] [Originally Added On: June 8th, 2014]
- Wolf of Wall Street & Cryptocurrency w/ Patrick "PK" McDonnell - Video [Last Updated On: June 9th, 2014] [Originally Added On: June 9th, 2014]
- BankNote CryptoCurrency Review - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- CryptoCurrency 4 Housing for Father's Day! - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- Hyper CryptoCurrency Review - Video [Last Updated On: June 14th, 2014] [Originally Added On: June 14th, 2014]
- 0NE " EPIC " (HD dubstep mix) spot - a cryptocurrency with an Engine - Video [Last Updated On: June 15th, 2014] [Originally Added On: June 15th, 2014]
- Bitcoin,Litecoin mining rig cryptocurrency 2500W system, 6x 280x ASUS Beast 2014 - Video [Last Updated On: June 17th, 2014] [Originally Added On: June 17th, 2014]
- The Rundown Live #281 Tatiana Moroz (Chemtrails,CryptoCurrency,Anti-War) - Video [Last Updated On: June 19th, 2014] [Originally Added On: June 19th, 2014]
- Neutrality Coin New Alternative Cryptocurrency - Video [Last Updated On: June 20th, 2014] [Originally Added On: June 20th, 2014]
- Cryptocurrency Update - Buy Low, Sell High! - Video [Last Updated On: June 21st, 2014] [Originally Added On: June 21st, 2014]