revealed

Slow Fog Cosine: Confirmed that the attacker of the CEX theft incident is the North Korean hacker group Lazarus Group, which has revealed its attack methods

ChainCatcher news, Slow Mist founder Yu Xian posted on social media, "Through forensic analysis and correlation tracking, we confirm that the attackers of the CEX theft incident are the North Korean hacker group Lazarus Group. This is a nation-state APT attack targeting cryptocurrency trading platforms. We have decided to share the relevant IOCs (Indicators of Compromise), which include some IPs of cloud service providers, proxies, etc. It is important to note that this disclosure does not specify which platform or platforms were involved, nor does it mention Bybit; if there are similarities, it is indeed not impossible."The attackers utilized pyyaml for RCE (Remote Code Execution), enabling the delivery of malicious code to control target computers and servers. This method bypassed most antivirus software. After synchronizing intelligence with partners, multiple similar malicious samples were obtained. The main goal of the attackers is to gain control over wallets by infiltrating the infrastructure of cryptocurrency trading platforms, thereby illegally transferring a large amount of cryptocurrency assets from the wallets.Slow Mist published a summary article revealing the attack methods of the Lazarus Group, and also analyzed their use of social engineering, vulnerability exploitation, privilege escalation, internal network penetration, and fund transfer tactics. At the same time, based on actual cases, they summarized defense recommendations against APT attacks, hoping to provide references for the industry and help more institutions enhance their security capabilities and reduce the impact of potential threats.

Official statement from Argentina: President Javier Milei will immediately transfer LIBRA-related matters to the Anti-Corruption Office and promises a thorough investigation until the truth is revealed

ChainCatcher news, according to the Argentine presidential office: "On October 19, 2024, President Javier Milei met with representatives of KIP Protocol in Argentina. During this meeting, the company representatives presented the president with their intention to develop a project called 'Viva la Libertad' ('Long Live Freedom'), which aims to utilize blockchain technology to provide financing for private enterprises in Argentina.This meeting has been officially recorded in the public hearing registry, with participants including the national president, KIP Protocol representatives Mauricio Novelli and Julian Peh, as well as presidential spokesperson Manuel Adorni.In this context, on January 30, 2025, the president met with Hayden Mark Davis at the Casa Rosada (Rose Palace). According to the introduction by KIP Protocol representatives, Mr. Davis will provide the technical infrastructure for the project. Mr. Davis has had no prior association with the Argentine government, nor has he established any relationship with it; he was referred as a project partner by representatives of KIP Protocol.Finally, yesterday, the president posted a message on his personal social media account announcing the launch of the KIP Protocol project, similar to his usual support for many entrepreneurs looking to start projects in Argentina to create jobs and attract investment. Due to the widespread attention the project launch received, and to avoid any speculation and reduce further dissemination, the president decided to delete this post.In light of the above, President Javier Milei has decided to immediately refer this matter to the Anti-Corruption Office (OA) to determine whether there has been any misconduct by any members of the national government, including the president himself, in this incident.Additionally, the national president has decided to establish an investigative task force (UTI) under the presidential office, which will consist of representatives from institutions and departments related to cryptocurrency, financial activities, money laundering, and other relevant fields, to consolidate information for an urgent investigation into the release of the cryptocurrency LIBRA and all related businesses or individuals.All information collected during the investigation will be handed over to the judicial authorities to determine whether any businesses or individuals associated with the KIP Protocol project are suspected of criminal activity.President Milei has demonstrated his commitment to the pursuit of truth through concrete actions and has pledged to thoroughly investigate this incident until the truth is revealed."
ChainCatcher Building the Web3 world with innovators