TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies
Cosa significa
CISA Cybersecurity Advisories ha pubblicato l'advisory "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.
Perché conta
La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.
Azioni consigliate
- Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Last Revised April 20, 2022 Alert Code AA22-108A Summary Actions to take today to mitigate cyber threats to cryptocurrency: • Patch all systems. • Prioritize patching known exploited vulnerabilities . • Train users to recognize and report phishing attempts . • Use multifactor authentication . The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Treasury Department (Treasury) are issuing this joint Cybersecurity Advisory (CSA) to highlight the cyber threat associated with cryptocurrency thefts and tactics used by a North Korean state-sponsored advanced persistent threat (APT) group since at least 2020. This group is commonly tracked by the cybersecurity industry as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. For more information on North Korean state-sponsored malicious cyber activity, visit https://www.us-cert.cisa.gov/northkorea . The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). The activity described in this advisory involves social engineering of victims using a variety of communication platforms to encourage individuals to download trojanized cryptocu
Indicatori CISA verificabili
74 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T07:02:09.156137+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| url | https://github[.]com/dafomdev | |
| url | https://aideck[.]net/board[.]php | |
| ipv4-addr | 107[.]154[.]160[.]132 | |
| ipv4-addr | 46[.]16[.]62[.]238 | |
| ipv4-addr | 185[.]66[.]41[.]17 | |
| ipv4-addr | 151[.]101[.]64[.]119 | |
| ipv4-addr | 62[.]84[.]240[.]140 | |
| url | https://www[.]esilet[.]com/update/ | |
| url | https://www[.]alticgo[.]com/update/ | |
| ipv4-addr | 89[.]45[.]4[.]151 | |
| ipv4-addr | 199[.]188[.]103[.]115 | |
| ipv4-addr | 45[.]14[.]227[.]58 | |
| domain-name | dafom[.]dev | |
| MD5 | c2ea5011a91cd59d0396eb4fa8da7d21 | DAFOM-1.0.0.dmg |
| SHA-1 | b2d9ca7b6d1bbbe4864ea11dfca343b7e15597d8 | DAFOM-1.0.0.dmg |
| SHA-256 | 60b3cfe2ec3100caf4afde734cfd5147f78acf58ab17d4480196831db4aa5f18 | DAFOM-1.0.0.dmg |
| SSDEEP | 1572864:LGLBnolF9kPEiKOabR2QEs1B1/LuUQrbecE6Xwijkca/pzpfaLtIP:LGVnoT9kPZK9tVEwBxWbecR5Faxzpf0M | DAFOM-1.0.0.dmg |
| MD5 | 930f6f729e5c4d5fb52189338e549e5e | TokenAIS.app.zip |
| SHA-1 | 8e67006585e49f51db96604487138e688df732d3 | TokenAIS.app.zip |
| SHA-256 | 5b40b73934c1583144f41d8463e227529fa7157e26e6012babd062e3fd7e0b03 | TokenAIS.app.zip |
| SSDEEP | 3145728:aMFJlKVvw4+zLruAsHrmo5Vvw4+zLruAsHrmob0dC/E:aUlKtw4+/r2HNtw4+/r2HnMCM | TokenAIS.app.zip |
| MD5 | 4e5ebbecd22c939f0edf1d16d68e8490 | CryptAIS.dmg |
| SHA-1 | f1606d4d374d7e2ba756bdd4df9b780748f6dc98 | CryptAIS.dmg |
| SHA-256 | f0e8c29e3349d030a97f4a8673387c2e21858cccd1fb9ebbf9009b27743b2e5b | CryptAIS.dmg |
| SSDEEP | 1572864:jx9QOwiLDCUrJXsKMoGTwiCcKFI8jmrvGqjL2hX6QklBmrZgkZjMz+dPSpR0Xcpk:F9QOTPCUrdsKEw3coIg2Or6XBmrZgkZw | CryptAIS.dmg |
| domain-name | tokenais[.]com | |
| domain-name | cryptais[.]com | |
| ipv4-addr | 82[.]102[.]31[.]14 | |
| ipv4-addr | 104[.]168[.]98[.]156 | |
| ipv4-addr | 38[.]132[.]124[.]161 | |
| MD5 | 855b2f4c910602f895ee3c94118e979a | alticgo_r.exe |
| SHA-1 | ff17bd5abe9f4939918f27afbe0072c18df6db37 | alticgo_r.exe |
| SHA-256 | e3d98cc4539068ce335f1240deb1d72a0b57b9ca5803254616ea4999b66703ad | alticgo_r.exe |
| SSDEEP | 786432:LptZmVDkD1mQIiXUBkRbWGtqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yH:LpzKDgzRpWGwpAU6JXnJ46X+eC6cySiI | alticgo_r.exe |
| MD5 | 1c7d0ae1c4d2c0b70f75eab856327956 | alticgo.exe |
| SHA-1 | f3263451f8988a9b02268f0fb6893f7c41b906d9 | alticgo.exe |
| SHA-256 | 765a79d22330098884e0f7ce692d61c40dfcf288826342f33d976d8314cfd819 | alticgo.exe |
| SSDEEP | 786432:optZmVDkD1mZ1FggTqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yVPUXi7:opzKDginspAU6JXnJ46X+eC6cySihWVX | alticgo.exe |
| MD5 | 9578c2be6437dcc8517e78a5de1fa975 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SHA-1 | d2a77c31c3e169bec655068e96cf4e7fc52e77b8 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SHA-256 | dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SSDEEP | 384:sdaWs0fDTmKnY4FPk6hTyQUitnI/kmCgr7lUryESll4yg9RpEwrUifJ8ttJOdy:sdayCkY4Fei9mhy/L9RBrny6y | Esilet-tmp60nxh; esilet-tmpg7lpp |
| MD5 | 5d43baf1c9e9e3a939e5defd8f8fbd8d | win32.bin |
| SHA-1 | d5ff73c043f3bb75dd749636307500b60a436550 | win32.bin |
| SHA-256 | 867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc7dd36 | win32.bin |
| SSDEEP | 24576:y3SY+/2M3BMr7cdgSLBjbr4nzzy95VV7cEXV:ESZ2ESrHSV3D95oA | win32.bin |
| MD5 | 8397ea747d2ab50da4f876a36d673272 | darwin64.bin |
| SHA-1 | 48a6d5141e25b6c63ad8da20b954b56afe589031 | darwin64.bin |
| SHA-256 | 89b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e4aa15ccd7512b1e63957 | darwin64.bin |
| SSDEEP | 49152:KIH1kEh7zIXlDYwVhb26hRKtRwwfs62sRAdNhEJNDvOL3OXl5zpF+FqBNihzTvff:KIH1kEhI1LOJtm2spB | darwin64.bin |
| MD5 | 9a6307362e3331459d350a201ad66cd9 | alticgo.exe |
| SHA-1 | 3f2c1e60b5fac4cf1013e3e1fc688be490d71a84 | alticgo.exe |
| SHA-256 | 8acd7c2708eb1119ba64699fd702ebd96c0d59a66cba5059f4e089f4b0914925 | alticgo.exe |
| SSDEEP | 786432:AptZmVDkD1mjPNDeuxOTKQqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yV7:ApzKDgqPxeuLpAU6JXnJ46X+eC6cySiG | alticgo.exe |
| domain-name | aideck[.]net | |
| domain-name | infodigitalnew[.]com | |
| ipv4-addr | 160[.]153[.]235[.]20 | |
| domain-name | vinoymas[.]ch | |
| domain-name | sche-eg[.]org | |
| domain-name | creaideck[.]com | |
| domain-name | alticgo[.]com | |
| domain-name | haciendadeclarevot[.]com | |
| domain-name | greenvideo[.]nl | |
| domain-name | dafnefonseca[.]com | |
| MD5 | 1ca31319721740ecb79f4b9ee74cd9b0 | Esilet-tmpzpsb3; top.php |
| SHA-1 | 41f855b54bf3db621b340b7c59722fb493ba39a5 | Esilet-tmpzpsb3; top.php |
| SHA-256 | 9d9dda39af17a37d92b429b68f4a8fc0a76e93ff1bd03f06258c51b73eb40efa | Esilet-tmpzpsb3; top.php |
| SSDEEP | 6144:wAulcT94T94T97zDj1I/BkjhkbjZ8bZ87ZMSj71obV/7NobNo7NZTb7hMT5ETZ8I:wDskT1UBg2lirFbpR9mJGpmN | Esilet-tmpzpsb3; top.php |
| MD5 | 53d9af8829a9c7f6f177178885901c01 | esilet.dmg |
| SHA-1 | ae9f4e39c576555faadee136c6c3b2d358ad90b9 | esilet.dmg |
| SHA-256 | 9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598 | esilet.dmg |
| SSDEEP | 1572864:lffyoUnp5xmHVUTd+GgNPjFvp4YEbRU7h8cvjmUAm4Du73X0unpXkU:lfqHBmHo+BPj9CYEshLqcuAX0I0 | esilet.dmg |
| domain-name | esilet[.]com | |
| ipv4-addr | 108[.]170[.]55[.]202 |
Provenienza
Allegato ufficiale CISA · 2022-04-20T02:54:59Z
SHA-512: 8a71d13f12d27fc399024698a471529b07bc4828ff9c908c9d148aac068fe1214cb7fcbdffcd728a3d557d711218bb7d4b26afaf1295b5f005f34b768f6acf59
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 20/04/2022 14:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1071.001, T1552.004, T1566.001
- Classificazione
- Critica
- Paese indicato
- US
Azione indicata dalla fonte
Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.