EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato l'advisory "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.

Why it matters

La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISO
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Last Revised April 20, 2022 Alert Code AA22-108A Summary Actions to take today to mitigate cyber threats to cryptocurrency: • Patch all systems. • Prioritize patching known exploited vulnerabilities . • Train users to recognize and report phishing attempts . • Use multifactor authentication . The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Treasury Department (Treasury) are issuing this joint Cybersecurity Advisory (CSA) to highlight the cyber threat associated with cryptocurrency thefts and tactics used by a North Korean state-sponsored advanced persistent threat (APT) group since at least 2020. This group is commonly tracked by the cybersecurity industry as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. For more information on North Korean state-sponsored malicious cyber activity, visit https://www.us-cert.cisa.gov/northkorea . The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). The activity described in this advisory involves social engineering of victims using a variety of communication platforms to encourage individuals to download trojanized cryptocu

Indicatori CISA verificabili

74 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T07:02:09.156137+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttps://github[.]com/dafomdev
urlhttps://aideck[.]net/board[.]php
ipv4-addr107[.]154[.]160[.]132
ipv4-addr46[.]16[.]62[.]238
ipv4-addr185[.]66[.]41[.]17
ipv4-addr151[.]101[.]64[.]119
ipv4-addr62[.]84[.]240[.]140
urlhttps://www[.]esilet[.]com/update/
urlhttps://www[.]alticgo[.]com/update/
ipv4-addr89[.]45[.]4[.]151
ipv4-addr199[.]188[.]103[.]115
ipv4-addr45[.]14[.]227[.]58
domain-namedafom[.]dev
MD5c2ea5011a91cd59d0396eb4fa8da7d21DAFOM-1.0.0.dmg
SHA-1b2d9ca7b6d1bbbe4864ea11dfca343b7e15597d8DAFOM-1.0.0.dmg
SHA-25660b3cfe2ec3100caf4afde734cfd5147f78acf58ab17d4480196831db4aa5f18DAFOM-1.0.0.dmg
SSDEEP1572864:LGLBnolF9kPEiKOabR2QEs1B1/LuUQrbecE6Xwijkca/pzpfaLtIP:LGVnoT9kPZK9tVEwBxWbecR5Faxzpf0MDAFOM-1.0.0.dmg
MD5930f6f729e5c4d5fb52189338e549e5eTokenAIS.app.zip
SHA-18e67006585e49f51db96604487138e688df732d3TokenAIS.app.zip
SHA-2565b40b73934c1583144f41d8463e227529fa7157e26e6012babd062e3fd7e0b03TokenAIS.app.zip
SSDEEP3145728:aMFJlKVvw4+zLruAsHrmo5Vvw4+zLruAsHrmob0dC/E:aUlKtw4+/r2HNtw4+/r2HnMCMTokenAIS.app.zip
MD54e5ebbecd22c939f0edf1d16d68e8490CryptAIS.dmg
SHA-1f1606d4d374d7e2ba756bdd4df9b780748f6dc98CryptAIS.dmg
SHA-256f0e8c29e3349d030a97f4a8673387c2e21858cccd1fb9ebbf9009b27743b2e5bCryptAIS.dmg
SSDEEP1572864:jx9QOwiLDCUrJXsKMoGTwiCcKFI8jmrvGqjL2hX6QklBmrZgkZjMz+dPSpR0Xcpk:F9QOTPCUrdsKEw3coIg2Or6XBmrZgkZwCryptAIS.dmg
domain-nametokenais[.]com
domain-namecryptais[.]com
ipv4-addr82[.]102[.]31[.]14
ipv4-addr104[.]168[.]98[.]156
ipv4-addr38[.]132[.]124[.]161
MD5855b2f4c910602f895ee3c94118e979aalticgo_r.exe
SHA-1ff17bd5abe9f4939918f27afbe0072c18df6db37alticgo_r.exe
SHA-256e3d98cc4539068ce335f1240deb1d72a0b57b9ca5803254616ea4999b66703adalticgo_r.exe
SSDEEP786432:LptZmVDkD1mQIiXUBkRbWGtqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yH:LpzKDgzRpWGwpAU6JXnJ46X+eC6cySiIalticgo_r.exe
MD51c7d0ae1c4d2c0b70f75eab856327956alticgo.exe
SHA-1f3263451f8988a9b02268f0fb6893f7c41b906d9alticgo.exe
SHA-256765a79d22330098884e0f7ce692d61c40dfcf288826342f33d976d8314cfd819alticgo.exe
SSDEEP786432:optZmVDkD1mZ1FggTqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yVPUXi7:opzKDginspAU6JXnJ46X+eC6cySihWVXalticgo.exe
MD59578c2be6437dcc8517e78a5de1fa975Esilet-tmp60nxh; esilet-tmpg7lpp
SHA-1d2a77c31c3e169bec655068e96cf4e7fc52e77b8Esilet-tmp60nxh; esilet-tmpg7lpp
SHA-256dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156Esilet-tmp60nxh; esilet-tmpg7lpp
SSDEEP384:sdaWs0fDTmKnY4FPk6hTyQUitnI/kmCgr7lUryESll4yg9RpEwrUifJ8ttJOdy:sdayCkY4Fei9mhy/L9RBrny6yEsilet-tmp60nxh; esilet-tmpg7lpp
MD55d43baf1c9e9e3a939e5defd8f8fbd8dwin32.bin
SHA-1d5ff73c043f3bb75dd749636307500b60a436550win32.bin
SHA-256867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc7dd36win32.bin
SSDEEP24576:y3SY+/2M3BMr7cdgSLBjbr4nzzy95VV7cEXV:ESZ2ESrHSV3D95oAwin32.bin
MD58397ea747d2ab50da4f876a36d673272darwin64.bin
SHA-148a6d5141e25b6c63ad8da20b954b56afe589031darwin64.bin
SHA-25689b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e4aa15ccd7512b1e63957darwin64.bin
SSDEEP49152:KIH1kEh7zIXlDYwVhb26hRKtRwwfs62sRAdNhEJNDvOL3OXl5zpF+FqBNihzTvff:KIH1kEhI1LOJtm2spBdarwin64.bin
MD59a6307362e3331459d350a201ad66cd9alticgo.exe
SHA-13f2c1e60b5fac4cf1013e3e1fc688be490d71a84alticgo.exe
SHA-2568acd7c2708eb1119ba64699fd702ebd96c0d59a66cba5059f4e089f4b0914925alticgo.exe
SSDEEP786432:AptZmVDkD1mjPNDeuxOTKQqqLGAU6JXnjmDQ4YBXpleV0RnJYJKoSuDySLGh7yV7:ApzKDgqPxeuLpAU6JXnJ46X+eC6cySiGalticgo.exe
domain-nameaideck[.]net
domain-nameinfodigitalnew[.]com
ipv4-addr160[.]153[.]235[.]20
domain-namevinoymas[.]ch
domain-namesche-eg[.]org
domain-namecreaideck[.]com
domain-namealticgo[.]com
domain-namehaciendadeclarevot[.]com
domain-namegreenvideo[.]nl
domain-namedafnefonseca[.]com
MD51ca31319721740ecb79f4b9ee74cd9b0Esilet-tmpzpsb3; top.php
SHA-141f855b54bf3db621b340b7c59722fb493ba39a5Esilet-tmpzpsb3; top.php
SHA-2569d9dda39af17a37d92b429b68f4a8fc0a76e93ff1bd03f06258c51b73eb40efaEsilet-tmpzpsb3; top.php
SSDEEP6144:wAulcT94T94T97zDj1I/BkjhkbjZ8bZ87ZMSj71obV/7NobNo7NZTb7hMT5ETZ8I:wDskT1UBg2lirFbpR9mJGpmNEsilet-tmpzpsb3; top.php
MD553d9af8829a9c7f6f177178885901c01esilet.dmg
SHA-1ae9f4e39c576555faadee136c6c3b2d358ad90b9esilet.dmg
SHA-2569ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598esilet.dmg
SSDEEP1572864:lffyoUnp5xmHVUTd+GgNPjFvp4YEbRU7h8cvjmUAm4Du73X0unpXkU:lfqHBmHo+BPj9CYEshLqcuAX0I0esilet.dmg
domain-nameesilet[.]com
ipv4-addr108[.]170[.]55[.]202

Provenance

Allegato ufficiale CISA · 2022-04-20T02:54:59Z

SHA-512: 8a71d13f12d27fc399024698a471529b07bc4828ff9c908c9d148aac068fe1214cb7fcbdffcd728a3d557d711218bb7d4b26afaf1295b5f005f34b768f6acf59

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
20/04/2022 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1071.001, T1552.004, T1566.001
Classification
Critical
Stated country
US

Action indicated by the source

Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.

Official technical references

Open the original source