TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies
What it means
CISA Cybersecurity Advisories ha pubblicato l'advisory "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.
Why it matters
La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.
Recommended actions
- Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Potential operational benefits
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Last Revised April 20, 2022 Alert Code AA22-108A Summary Actions to take today to mitigate cyber threats to cryptocurrency: • Patch all systems. • Prioritize patching known exploited vulnerabilities . • Train users to recognize and report phishing attempts . • Use multifactor authentication . The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Treasury Department (Treasury) are issuing this joint Cybersecurity Advisory (CSA) to highlight the cyber threat associated with cryptocurrency thefts and tactics used by a North Korean state-sponsored advanced persistent threat (APT) group since at least 2020. This group is commonly tracked by the cybersecurity industry as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. For more information on North Korean state-sponsored malicious cyber activity, visit https://www.us-cert.cisa.gov/northkorea . The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). The activity described in this advisory involves social engineering of victims using a variety of communication platforms to encourage individuals to download trojanized cryptocu
Indicatori CISA verificabili
74 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T07:02:09.156137+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| url | https://github[.]com/dafomdev | |
| url | https://aideck[.]net/board[.]php | |
| ipv4-addr | 107[.]154[.]160[.]132 | |
| ipv4-addr | 46[.]16[.]62[.]238 | |
| ipv4-addr | 185[.]66[.]41[.]17 | |
| ipv4-addr | 151[.]101[.]64[.]119 | |
| ipv4-addr | 62[.]84[.]240[.]140 | |
| url | https://www[.]esilet[.]com/update/ | |
| url | https://www[.]alticgo[.]com/update/ | |
| ipv4-addr | 89[.]45[.]4[.]151 | |
| ipv4-addr | 199[.]188[.]103[.]115 | |
| ipv4-addr | 45[.]14[.]227[.]58 | |
| domain-name | dafom[.]dev | |
| MD5 | c2ea5011a91cd59d0396eb4fa8da7d21 | DAFOM-1.0.0.dmg |
| SHA-1 | b2d9ca7b6d1bbbe4864ea11dfca343b7e15597d8 | DAFOM-1.0.0.dmg |
| SHA-256 | 60b3cfe2ec3100caf4afde734cfd5147f78acf58ab17d4480196831db4aa5f18 | DAFOM-1.0.0.dmg |
| SSDEEP | 1572864:LGLBnolF9kPEiKOabR2QEs1B1/LuUQrbecE6Xwijkca/pzpfaLtIP:LGVnoT9kPZK9tVEwBxWbecR5Faxzpf0M | DAFOM-1.0.0.dmg |
| MD5 | 930f6f729e5c4d5fb52189338e549e5e | TokenAIS.app.zip |
| SHA-1 | 8e67006585e49f51db96604487138e688df732d3 | TokenAIS.app.zip |
| SHA-256 | 5b40b73934c1583144f41d8463e227529fa7157e26e6012babd062e3fd7e0b03 | TokenAIS.app.zip |
| SSDEEP | 3145728:aMFJlKVvw4+zLruAsHrmo5Vvw4+zLruAsHrmob0dC/E:aUlKtw4+/r2HNtw4+/r2HnMCM | TokenAIS.app.zip |
| MD5 | 4e5ebbecd22c939f0edf1d16d68e8490 | CryptAIS.dmg |
| SHA-1 | f1606d4d374d7e2ba756bdd4df9b780748f6dc98 | CryptAIS.dmg |
| SHA-256 | f0e8c29e3349d030a97f4a8673387c2e21858cccd1fb9ebbf9009b27743b2e5b | CryptAIS.dmg |
| SSDEEP | 1572864:jx9QOwiLDCUrJXsKMoGTwiCcKFI8jmrvGqjL2hX6QklBmrZgkZjMz+dPSpR0Xcpk:F9QOTPCUrdsKEw3coIg2Or6XBmrZgkZw | CryptAIS.dmg |
| domain-name | tokenais[.]com | |
| domain-name | cryptais[.]com | |
| ipv4-addr | 82[.]102[.]31[.]14 | |
| ipv4-addr | 104[.]168[.]98[.]156 | |
| ipv4-addr | 38[.]132[.]124[.]161 | |
| MD5 | 855b2f4c910602f895ee3c94118e979a | alticgo_r.exe |
| SHA-1 | ff17bd5abe9f4939918f27afbe0072c18df6db37 | alticgo_r.exe |
| SHA-256 | e3d98cc4539068ce335f1240deb1d72a0b57b9ca5803254616ea4999b66703ad | alticgo_r.exe |
| SSDEEP | 786432:LptZmVDkD1mQIiXUBkRbWGtqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yH:LpzKDgzRpWGwpAU6JXnJ46X+eC6cySiI | alticgo_r.exe |
| MD5 | 1c7d0ae1c4d2c0b70f75eab856327956 | alticgo.exe |
| SHA-1 | f3263451f8988a9b02268f0fb6893f7c41b906d9 | alticgo.exe |
| SHA-256 | 765a79d22330098884e0f7ce692d61c40dfcf288826342f33d976d8314cfd819 | alticgo.exe |
| SSDEEP | 786432:optZmVDkD1mZ1FggTqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yVPUXi7:opzKDginspAU6JXnJ46X+eC6cySihWVX | alticgo.exe |
| MD5 | 9578c2be6437dcc8517e78a5de1fa975 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SHA-1 | d2a77c31c3e169bec655068e96cf4e7fc52e77b8 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SHA-256 | dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156 | Esilet-tmp60nxh; esilet-tmpg7lpp |
| SSDEEP | 384:sdaWs0fDTmKnY4FPk6hTyQUitnI/kmCgr7lUryESll4yg9RpEwrUifJ8ttJOdy:sdayCkY4Fei9mhy/L9RBrny6y | Esilet-tmp60nxh; esilet-tmpg7lpp |
| MD5 | 5d43baf1c9e9e3a939e5defd8f8fbd8d | win32.bin |
| SHA-1 | d5ff73c043f3bb75dd749636307500b60a436550 | win32.bin |
| SHA-256 | 867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc7dd36 | win32.bin |
| SSDEEP | 24576:y3SY+/2M3BMr7cdgSLBjbr4nzzy95VV7cEXV:ESZ2ESrHSV3D95oA | win32.bin |
| MD5 | 8397ea747d2ab50da4f876a36d673272 | darwin64.bin |
| SHA-1 | 48a6d5141e25b6c63ad8da20b954b56afe589031 | darwin64.bin |
| SHA-256 | 89b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e4aa15ccd7512b1e63957 | darwin64.bin |
| SSDEEP | 49152:KIH1kEh7zIXlDYwVhb26hRKtRwwfs62sRAdNhEJNDvOL3OXl5zpF+FqBNihzTvff:KIH1kEhI1LOJtm2spB | darwin64.bin |
| MD5 | 9a6307362e3331459d350a201ad66cd9 | alticgo.exe |
| SHA-1 | 3f2c1e60b5fac4cf1013e3e1fc688be490d71a84 | alticgo.exe |
| SHA-256 | 8acd7c2708eb1119ba64699fd702ebd96c0d59a66cba5059f4e089f4b0914925 | alticgo.exe |
| SSDEEP | 786432:AptZmVDkD1mjPNDeuxOTKQqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yV7:ApzKDgqPxeuLpAU6JXnJ46X+eC6cySiG | alticgo.exe |
| domain-name | aideck[.]net | |
| domain-name | infodigitalnew[.]com | |
| ipv4-addr | 160[.]153[.]235[.]20 | |
| domain-name | vinoymas[.]ch | |
| domain-name | sche-eg[.]org | |
| domain-name | creaideck[.]com | |
| domain-name | alticgo[.]com | |
| domain-name | haciendadeclarevot[.]com | |
| domain-name | greenvideo[.]nl | |
| domain-name | dafnefonseca[.]com | |
| MD5 | 1ca31319721740ecb79f4b9ee74cd9b0 | Esilet-tmpzpsb3; top.php |
| SHA-1 | 41f855b54bf3db621b340b7c59722fb493ba39a5 | Esilet-tmpzpsb3; top.php |
| SHA-256 | 9d9dda39af17a37d92b429b68f4a8fc0a76e93ff1bd03f06258c51b73eb40efa | Esilet-tmpzpsb3; top.php |
| SSDEEP | 6144:wAulcT94T94T97zDj1I/BkjhkbjZ8bZ87ZMSj71obV/7NobNo7NZTb7hMT5ETZ8I:wDskT1UBg2lirFbpR9mJGpmN | Esilet-tmpzpsb3; top.php |
| MD5 | 53d9af8829a9c7f6f177178885901c01 | esilet.dmg |
| SHA-1 | ae9f4e39c576555faadee136c6c3b2d358ad90b9 | esilet.dmg |
| SHA-256 | 9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598 | esilet.dmg |
| SSDEEP | 1572864:lffyoUnp5xmHVUTd+GgNPjFvp4YEbRU7h8cvjmUAm4Du73X0unpXkU:lfqHBmHo+BPj9CYEshLqcuAX0I0 | esilet.dmg |
| domain-name | esilet[.]com | |
| ipv4-addr | 108[.]170[.]55[.]202 |
Provenance
Allegato ufficiale CISA · 2022-04-20T02:54:59Z
SHA-512: 8a71d13f12d27fc399024698a471529b07bc4828ff9c908c9d148aac068fe1214cb7fcbdffcd728a3d557d711218bb7d4b26afaf1295b5f005f34b768f6acf59
- Source
- CISA Cybersecurity Advisories
- Publishing entity
- CISA
- Entity type
- National authority
- Area
- North America · US
- Original language
- en · translation in preparation
- Publication
- 20/04/2022 14:00
- Sharing
- TLP:CLEAR
- MITRE ATT&CK
- T1071.001, T1552.004, T1566.001
- Classification
- Critical
- Stated country
- US
Action indicated by the source
Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.