BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home GUIDES

Phishing Tactic Revealed As North Korean Hackers Cart-Away With NFTs

BlockNews Team by BlockNews Team
December 30, 2022
in GUIDES, MEDIA, NFT, SOCIAL
Reading Time: 4 mins read
1
SHARES
18
VIEWS
Share on XShare in TelegramShare on Reddit
  • Phishing tactics by North Korean hackers revealed by SlowMist.
  • North Korea is listed as one of the countries with an active cryptocurrency crime in 2022.
  • The North Korean Advanced Persistent Threat (APT) group has stolen NFTs in the guise of phishing websites.

While the world was celebrating the festive season, a North Korean Advanced Persistent Threat (APT) group was gearing up to commit one of the most heinous crimes known in the industry by stealing NFT (Non-Fungible Token) projects from NFT investors, using 500 malicious phishing websites. 

The crypto industry has experienced a lot of scams and theft this year, and it looks like hackers are not closing for the year as the North Korean APT group, which has been linked to the cybercrime group ‘Lazarus Group,’ has been discovered by SlowMist, a Blockchain security firm.

SlowMist released a report, alerting everyone about the tactics these criminals used to rob victims of their NFTs worth $360,000. The Blockchain security firm explained that the cyber-criminals created convincing decoy websites, emulating NFT projects and popular NFT marketplaces like Opensea, Rarible, X2Y2, and more.

One of the tactics employed by the hackers was tricking unknowing NFT investors and traders into interacting with these pseudo websites offering “malicious minting.” With this, victims assumed they would be minting a genuine NFT, whereas they were giving access to their details by connecting their wallets to phishing websites.

“Upon further investigation, we found that one of the techniques used in this phishing attack involved creating fake NFT-related decoy websites with malicious mints,” SlowMint had written.

The hackers targeted NFT investors, using almost 500 phishing websites to lure their victims into their scheme, and made away with 1,055 NFTs (Non-Fungible Tokens).

According to SlowMist, the North Korean hackers had deployed and operated many phishing websites, some pretending to be projects related to the World Cup. The NFTs being minted by investors are fraudulent because they leave the investors’ wallets easily accessible for the hackers to cart away everything in the investor’s wallets.

SlowMist reported that about 372 phishing websites were registered to a single Internet Protocol (IP), while 320 NFT phishing websites were registered to another IP. The Blockchain security firm also affirmed that after conducting a background check on the phishing websites, the result showed that the earliest registration of the domains could be traced back to seven months ago.

SlowMist recognized three traits to have been commonly utilized by North Korean hackers, and the security firm explained these traits to be:

  1. The phishing domains were built to store victims’ data on external servers. The cyber-criminals then record the information to an external website using an “HTTP GET” request.
  2. The phishing domain requested an NFT item price list.
  3. As part of the phishing site template, there was a file “imgScr.js” connecting images to the specified project containing lists of the target and the hosting direction of the image documents used on their corresponding phishing websites.

Several attack scripts were executed against the victims when the hackers were about to retrieve their data; these attack scripts enabled the hackers to access the victim’s authorizations, sigData, records, and use of plug-in wallets.

2022 has witnessed a surge in crypto crimes from North Korea as the Advanced Persistent Threat group was identified to have drained 1,055 NFTs worth 300 ETH from one phishing website, using its tactics.

Earlier in September, a Twitter user, PhantomXSec, had accused the North Korean APT group of being the mastermind behind NFT and crypto phishing campaigns targeting several SOL and ETH projects.

“North Korean APT group responsible for crypto and NFT phishing campaigns spanning 190 domains… campaign activity began in April and is ongoing,” PhantomXSec said.

Last year, Prevailing also called out the North Korean APT group for running a phishing campaign,” North Korean APT #Lazarus is running a #spearphishing campaign targeting defense companies with advanced malware called #ThreatNeedle.”

How to Avoid Phishing Websites?

1. Be Updated About The Latest Phishing Scams

New phishing scam methods are being developed constantly, and one of the best ways to get ahead of these scams and protect yourself and your digital assets is to learn about every new and latest phishing scam method.

2. Download an Anti-Phishing Toolbar

Install a practical internet browser that allows for the customization of anti-phishing toolbars. These toolbars could run a background check on visited websites and compare them against known phishing sites.

Conclusion

SlowMist, a Blockchain security firm, has uncovered the phishing tactics being employed by the North Korean Advanced Persistent Threat group to steal NFTs from NFT investors and projects. What does this dark cloud over the North Korean crypto industry mean for its users?

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: NFTNFTsNorth KoreaSlowMist
TweetShareShare
BlockNews Team

BlockNews Team

DON'T MISS THESE! HOT OFF THE PRESS

How to Go From Zero to Your First Profitable Trade in Crypto (2025)
BITCOIN

How to Go From Zero to Your First Profitable Trade in Crypto (2025)

September 17, 2025
What is Arbitrum? Why ARB is an Underpriced Crypto Gem Hiding in Plain Sight
CRYPTO

What is Arbitrum? Why ARB is an Underpriced Crypto Gem Hiding in Plain Sight

September 17, 2025
Alex Becker Crashes PumpFun with STRSZN Token Launch: Here is What Happened
CRYPTO

Alex Becker Crashes PumpFun with STRSZN Token Launch: Here is What Happened

September 15, 2025
Top 5 Crypto Fundamentals Every Trader Needs Before the Next Bull Run
CRYPTO

Top 5 Crypto Fundamentals Every Trader Needs Before the Next Bull Run

September 12, 2025
ApeCoin Makes Official Debut on Solana: Here is Why This is Bullish for APE Holders
CRYPTO

ApeCoin Makes Official Debut on Solana: Here is Why This is Bullish for APE Holders

September 9, 2025
Everything You Need to Know About the Senate Banking Committee’s New Crypto Market Structure Bill
BUSINESS

Everything You Need to Know About the Senate Banking Committee’s New Crypto Market Structure Bill

September 5, 2025
Load More

Related News

Ripple CEO Drops Bombshell: XRP Could Join White House Crypto Stockpile and ETF Approval Soon

September 18, 2025
Solana Faces “Most Important” Sell Wall Amid Whale Sell-Off Concerns

Solana Faces “Most Important” Sell Wall Amid Whale Sell-Off Concerns

September 18, 2025
Polygon Takes the Lead in RWA Market With $1.1B Locked, Dune Report Reveals

Polygon Takes the Lead in RWA Market With $1.1B Locked, Dune Report Reveals

September 18, 2025
Coinbase Teams Up with Ethereum Foundation on Open Intents Framework

Coinbase Teams Up with Ethereum Foundation on Open Intents Framework

September 18, 2025
Here is What Aave’s CEO Just Revealed About the Q4 2025 Upgrade

Here is What Aave’s CEO Just Revealed About the Q4 2025 Upgrade

September 17, 2025
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews