EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato l'advisory "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.

Perché conta

La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISO
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Last Revised April 20, 2022 Alert Code AA22-108A Summary Actions to take today to mitigate cyber threats to cryptocurrency: • Patch all systems. • Prioritize patching known exploited vulnerabilities . • Train users to recognize and report phishing attempts . • Use multifactor authentication . The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Treasury Department (Treasury) are issuing this joint Cybersecurity Advisory (CSA) to highlight the cyber threat associated with cryptocurrency thefts and tactics used by a North Korean state-sponsored advanced persistent threat (APT) group since at least 2020. This group is commonly tracked by the cybersecurity industry as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. For more information on North Korean state-sponsored malicious cyber activity, visit https://www.us-cert.cisa.gov/northkorea . The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). The activity described in this advisory involves social engineering of victims using a variety of communication platforms to encourage individuals to download trojanized cryptocu

Indicatori CISA verificabili

74 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T07:02:09.156137+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttps://github[.]com/dafomdev
urlhttps://aideck[.]net/board[.]php
ipv4-addr107[.]154[.]160[.]132
ipv4-addr46[.]16[.]62[.]238
ipv4-addr185[.]66[.]41[.]17
ipv4-addr151[.]101[.]64[.]119
ipv4-addr62[.]84[.]240[.]140
urlhttps://www[.]esilet[.]com/update/
urlhttps://www[.]alticgo[.]com/update/
ipv4-addr89[.]45[.]4[.]151
ipv4-addr199[.]188[.]103[.]115
ipv4-addr45[.]14[.]227[.]58
domain-namedafom[.]dev
MD5c2ea5011a91cd59d0396eb4fa8da7d21DAFOM-1.0.0.dmg
SHA-1b2d9ca7b6d1bbbe4864ea11dfca343b7e15597d8DAFOM-1.0.0.dmg
SHA-25660b3cfe2ec3100caf4afde734cfd5147f78acf58ab17d4480196831db4aa5f18DAFOM-1.0.0.dmg
SSDEEP1572864:LGLBnolF9kPEiKOabR2QEs1B1/LuUQrbecE6Xwijkca/pzpfaLtIP:LGVnoT9kPZK9tVEwBxWbecR5Faxzpf0MDAFOM-1.0.0.dmg
MD5930f6f729e5c4d5fb52189338e549e5eTokenAIS.app.zip
SHA-18e67006585e49f51db96604487138e688df732d3TokenAIS.app.zip
SHA-2565b40b73934c1583144f41d8463e227529fa7157e26e6012babd062e3fd7e0b03TokenAIS.app.zip
SSDEEP3145728:aMFJlKVvw4+zLruAsHrmo5Vvw4+zLruAsHrmob0dC/E:aUlKtw4+/r2HNtw4+/r2HnMCMTokenAIS.app.zip
MD54e5ebbecd22c939f0edf1d16d68e8490CryptAIS.dmg
SHA-1f1606d4d374d7e2ba756bdd4df9b780748f6dc98CryptAIS.dmg
SHA-256f0e8c29e3349d030a97f4a8673387c2e21858cccd1fb9ebbf9009b27743b2e5bCryptAIS.dmg
SSDEEP1572864:jx9QOwiLDCUrJXsKMoGTwiCcKFI8jmrvGqjL2hX6QklBmrZgkZjMz+dPSpR0Xcpk:F9QOTPCUrdsKEw3coIg2Or6XBmrZgkZwCryptAIS.dmg
domain-nametokenais[.]com
domain-namecryptais[.]com
ipv4-addr82[.]102[.]31[.]14
ipv4-addr104[.]168[.]98[.]156
ipv4-addr38[.]132[.]124[.]161
MD5855b2f4c910602f895ee3c94118e979aalticgo_r.exe
SHA-1ff17bd5abe9f4939918f27afbe0072c18df6db37alticgo_r.exe
SHA-256e3d98cc4539068ce335f1240deb1d72a0b57b9ca5803254616ea4999b66703adalticgo_r.exe
SSDEEP786432:LptZmVDkD1mQIiXUBkRbWGtqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yH:LpzKDgzRpWGwpAU6JXnJ46X+eC6cySiIalticgo_r.exe
MD51c7d0ae1c4d2c0b70f75eab856327956alticgo.exe
SHA-1f3263451f8988a9b02268f0fb6893f7c41b906d9alticgo.exe
SHA-256765a79d22330098884e0f7ce692d61c40dfcf288826342f33d976d8314cfd819alticgo.exe
SSDEEP786432:optZmVDkD1mZ1FggTqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yVPUXi7:opzKDginspAU6JXnJ46X+eC6cySihWVXalticgo.exe
MD59578c2be6437dcc8517e78a5de1fa975Esilet-tmp60nxh; esilet-tmpg7lpp
SHA-1d2a77c31c3e169bec655068e96cf4e7fc52e77b8Esilet-tmp60nxh; esilet-tmpg7lpp
SHA-256dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156Esilet-tmp60nxh; esilet-tmpg7lpp
SSDEEP384:sdaWs0fDTmKnY4FPk6hTyQUitnI/kmCgr7lUryESll4yg9RpEwrUifJ8ttJOdy:sdayCkY4Fei9mhy/L9RBrny6yEsilet-tmp60nxh; esilet-tmpg7lpp
MD55d43baf1c9e9e3a939e5defd8f8fbd8dwin32.bin
SHA-1d5ff73c043f3bb75dd749636307500b60a436550win32.bin
SHA-256867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc7dd36win32.bin
SSDEEP24576:y3SY+/2M3BMr7cdgSLBjbr4nzzy95VV7cEXV:ESZ2ESrHSV3D95oAwin32.bin
MD58397ea747d2ab50da4f876a36d673272darwin64.bin
SHA-148a6d5141e25b6c63ad8da20b954b56afe589031darwin64.bin
SHA-25689b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e4aa15ccd7512b1e63957darwin64.bin
SSDEEP49152:KIH1kEh7zIXlDYwVhb26hRKtRwwfs62sRAdNhEJNDvOL3OXl5zpF+FqBNihzTvff:KIH1kEhI1LOJtm2spBdarwin64.bin
MD59a6307362e3331459d350a201ad66cd9alticgo.exe
SHA-13f2c1e60b5fac4cf1013e3e1fc688be490d71a84alticgo.exe
SHA-2568acd7c2708eb1119ba64699fd702ebd96c0d59a66cba5059f4e089f4b0914925alticgo.exe
SSDEEP786432:AptZmVDkD1mjPNDeuxOTKQqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yV7:ApzKDgqPxeuLpAU6JXnJ46X+eC6cySiGalticgo.exe
domain-nameaideck[.]net
domain-nameinfodigitalnew[.]com
ipv4-addr160[.]153[.]235[.]20
domain-namevinoymas[.]ch
domain-namesche-eg[.]org
domain-namecreaideck[.]com
domain-namealticgo[.]com
domain-namehaciendadeclarevot[.]com
domain-namegreenvideo[.]nl
domain-namedafnefonseca[.]com
MD51ca31319721740ecb79f4b9ee74cd9b0Esilet-tmpzpsb3; top.php
SHA-141f855b54bf3db621b340b7c59722fb493ba39a5Esilet-tmpzpsb3; top.php
SHA-2569d9dda39af17a37d92b429b68f4a8fc0a76e93ff1bd03f06258c51b73eb40efaEsilet-tmpzpsb3; top.php
SSDEEP6144:wAulcT94T94T97zDj1I/BkjhkbjZ8bZ87ZMSj71obV/7NobNo7NZTb7hMT5ETZ8I:wDskT1UBg2lirFbpR9mJGpmNEsilet-tmpzpsb3; top.php
MD553d9af8829a9c7f6f177178885901c01esilet.dmg
SHA-1ae9f4e39c576555faadee136c6c3b2d358ad90b9esilet.dmg
SHA-2569ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598esilet.dmg
SSDEEP1572864:lffyoUnp5xmHVUTd+GgNPjFvp4YEbRU7h8cvjmUAm4Du73X0unpXkU:lfqHBmHo+BPj9CYEshLqcuAX0I0esilet.dmg
domain-nameesilet[.]com
ipv4-addr108[.]170[.]55[.]202

Provenienza

Allegato ufficiale CISA · 2022-04-20T02:54:59Z

SHA-512: 8a71d13f12d27fc399024698a471529b07bc4828ff9c908c9d148aac068fe1214cb7fcbdffcd728a3d557d711218bb7d4b26afaf1295b5f005f34b768f6acf59

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
20/04/2022 14:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1071.001, T1552.004, T1566.001
Classificazione
Critica
Paese indicato
US

Azione indicata dalla fonte

Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.

Riferimenti tecnici ufficiali

Apri la fonte originale