|
News North Korean hackers steal $36M from blockchain service using phishing emailAttackers siphoned funds from Humanity Protocol and minted tokens after infiltrating executive’s computer, report finds North Korean cybercriminals stole up to $36 million in cryptocurrency from a privacy-focused blockchain authentication platform earlier this month, continuing a spree of heists targeting decentralized services. In a report published Saturday, the identity verification service Humanity Protocol said attackers moved roughly 141.18 million Humanity ($H) tokens and minted additional currency on June 8 after infiltrating the service using stolen credentials. In total, the attackers stole 193,617,148 $H tokens, according to the company. Blockchain security firm Quantstamp, commissioned by Humanity Protocol to investigate the attack, attributed the campaign to North Korean actors based on the use of tools and tactics reminiscent of past DPRK operations. Quantstamp did not name a specific cybercriminal actor responsible for the social engineering-based operation, which serves as the latest addition to North Korea’s extensive track record as the world’s most prolific cryptocurrency thief. The Humanity Protocol theft follows other high-profile North Korea-linked campaigns targeting decentralized cryptocurrency services this year, including the $290 million KelpDAO and $285 million Drift Protocol heists in April. THEFT BY SOCIAL ENGINEERING The “targeted social-engineering attack” began with a phishing email sent to Chong Yee Wai, a Humanity Protocol director, according to the firm’s report. The email impersonated the South Korean cryptocurrency exchange Bithumb, with whom Chong was already in contact, and contained a link to a malicious attachment disguised as a document about a routine token circulation update. Mistakenly believing the file to be genuine, Chong clicked the link to download the attached compressed folder on June 5, and replied to the email after filling out the spreadsheet contained within the attachment. He also copied in his colleague Terence Kwok, who had received the same phishing email from the attackers. Once opened, the compressed file deployed a malware loader that had been digitally signed with a certificate linked to the South Korean office software company Hancom, whose proprietary file formats have often been exploited by North Korean cybercriminals to infiltrate targets’ computers. The malware gave the attackers full remote control over Chong’s computer, which they used to copy the target’s wallet on MetaMask — a popular virtual wallet and browser extension — and private authentication keys ahead of the June 8 heist. To maintain remote access while avoiding detection by security tools, the attackers installed Stas’m RDP Wrapper — a remote desktop session management program — and files posing as Microsoft Defender’s Network Inspection Service. Using the stolen wallet data and authentication keys, the North Korean actors quickly drained an account on the Ethereum blockchain, around 150 wallets holding $H tokens and a central wallet on June 8, according to Humanity Protocol. On Ethereum, the attackers upgraded a self-executing smart contract and stole 141.18 million $H tokens. On BNB Smart Chain (BSC), a blockchain network that supports smart contracts and decentralized applications, they exploited contract permissions and minted approximately 100 million new tokens without authorization. Within eight hours of the initial theft, the attackers funneled the stolen funds into a series of newly created wallets using decentralized exchanges including Uniswap and PancakeSwap, before consolidating the proceeds. According to Humanity Protocol, the attacker-controlled wallets held over $21 million in Ethereum as of Saturday, while the BSC proceeds were still being tracked. The identity verification service said on social media on Saturday that the Ethereum token contract has been frozen through a multisignature wallet outside the attackers’ control. However, the North Korean actors retain administrative control on BSC, potentially allowing them to continue minting tokens until Humanity Protocol can cut them off. Edited by Bryan Betts © Korea Risk Group. All rights reserved. |



