Lazarus Group stole $37 million from CoinsPaid through social engineering attacks
ChainCatcher news, the hacker group Lazarus Group stole $37 million from the Estonia-based crypto payment provider CoinsPaid through a 6-month social engineering attack. CoinsPaid stated that in March of this year, CoinsPaid's engineers received a list of questions regarding technical infrastructure, which came from a so-called "Ukrainian crypto processing startup." Between June and July, the engineers received fake job offers.
CoinsPaid reported that on July 22, an employee thought they were interviewing for a lucrative job and downloaded malware as part of a so-called technical test. The hacker group had spent 6 months learning about CoinsPaid, including team members, the company's structure, and all possible details. When the employee downloaded the malicious code, the hackers were able to access CoinsPaid's systems and successfully forged authorization requests to extract funds from CoinsPaid's hot wallet.