Untitled attachment
https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/449/467/710/810/251/original/35e5acafddc8279f.png
I spent nearly 4 months investigating the inner workings of a North Korean state-sponsored hacking group. Here's what I found:
- The group used generative AI tools to aid in almost every part of their operations.
- They exfiltrated 26,584 cryptocurrency wallets from victim systems, with a combined value totaling as much $12 million dollars.
- In several cases, the threat actors set up entire front companies to lure in developers via fake job posting, then infected them with malware.
- The threat actors successfully pulled off a supply-chain attack by compromising a VS Code extension developer's system.
🔗 Full article: https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.