BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
FOLLOW
BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
BlockNews

Phishing Tactic Revealed As North Korean Hackers Cart-Away With NFTs

by BlockNews Team
December 30, 2022
in Guides, Media, NFT, Social
A A
Phishing Tactic Revealed As North Korean Hackers Cart-Away With NFTs
1
SHARES
Share on TwitterShare on Reddit
  • Phishing tactics by North Korean hackers revealed by SlowMist.
  • North Korea is listed as one of the countries with an active cryptocurrency crime in 2022.
  • The North Korean Advanced Persistent Threat (APT) group has stolen NFTs in the guise of phishing websites.

While the world was celebrating the festive season, a North Korean Advanced Persistent Threat (APT) group was gearing up to commit one of the most heinous crimes known in the industry by stealing NFT (Non-Fungible Token) projects from NFT investors, using 500 malicious phishing websites. 

The crypto industry has experienced a lot of scams and theft this year, and it looks like hackers are not closing for the year as the North Korean APT group, which has been linked to the cybercrime group ‘Lazarus Group,’ has been discovered by SlowMist, a Blockchain security firm.

SlowMist released a report, alerting everyone about the tactics these criminals used to rob victims of their NFTs worth $360,000. The Blockchain security firm explained that the cyber-criminals created convincing decoy websites, emulating NFT projects and popular NFT marketplaces like Opensea, Rarible, X2Y2, and more.

One of the tactics employed by the hackers was tricking unknowing NFT investors and traders into interacting with these pseudo websites offering “malicious minting.” With this, victims assumed they would be minting a genuine NFT, whereas they were giving access to their details by connecting their wallets to phishing websites.

“Upon further investigation, we found that one of the techniques used in this phishing attack involved creating fake NFT-related decoy websites with malicious mints,” SlowMint had written.

The hackers targeted NFT investors, using almost 500 phishing websites to lure their victims into their scheme, and made away with 1,055 NFTs (Non-Fungible Tokens).

According to SlowMist, the North Korean hackers had deployed and operated many phishing websites, some pretending to be projects related to the World Cup. The NFTs being minted by investors are fraudulent because they leave the investors’ wallets easily accessible for the hackers to cart away everything in the investor’s wallets.

SlowMist reported that about 372 phishing websites were registered to a single Internet Protocol (IP), while 320 NFT phishing websites were registered to another IP. The Blockchain security firm also affirmed that after conducting a background check on the phishing websites, the result showed that the earliest registration of the domains could be traced back to seven months ago.

SlowMist recognized three traits to have been commonly utilized by North Korean hackers, and the security firm explained these traits to be:

  1. The phishing domains were built to store victims’ data on external servers. The cyber-criminals then record the information to an external website using an “HTTP GET” request.
  2. The phishing domain requested an NFT item price list.
  3. As part of the phishing site template, there was a file “imgScr.js” connecting images to the specified project containing lists of the target and the hosting direction of the image documents used on their corresponding phishing websites.

Several attack scripts were executed against the victims when the hackers were about to retrieve their data; these attack scripts enabled the hackers to access the victim’s authorizations, sigData, records, and use of plug-in wallets.

2022 has witnessed a surge in crypto crimes from North Korea as the Advanced Persistent Threat group was identified to have drained 1,055 NFTs worth 300 ETH from one phishing website, using its tactics.

Earlier in September, a Twitter user, PhantomXSec, had accused the North Korean APT group of being the mastermind behind NFT and crypto phishing campaigns targeting several SOL and ETH projects.

“North Korean APT group responsible for crypto and NFT phishing campaigns spanning 190 domains… campaign activity began in April and is ongoing,” PhantomXSec said.

Last year, Prevailing also called out the North Korean APT group for running a phishing campaign,” North Korean APT #Lazarus is running a #spearphishing campaign targeting defense companies with advanced malware called #ThreatNeedle.”

How to Avoid Phishing Websites?

1. Be Updated About The Latest Phishing Scams

New phishing scam methods are being developed constantly, and one of the best ways to get ahead of these scams and protect yourself and your digital assets is to learn about every new and latest phishing scam method.

2. Download an Anti-Phishing Toolbar

Install a practical internet browser that allows for the customization of anti-phishing toolbars. These toolbars could run a background check on visited websites and compare them against known phishing sites.

Conclusion

SlowMist, a Blockchain security firm, has uncovered the phishing tactics being employed by the North Korean Advanced Persistent Threat group to steal NFTs from NFT investors and projects. What does this dark cloud over the North Korean crypto industry mean for its users?

Tags: NFTNFTsNorth KoreaSlowMist
TweetShareShare

DON'T MISS THESE! HOT OFF THE PRESS

Yuga Labs Sells Off Moonbirds IP to Double Down on Bored Apes and Otherside — Bullish Signal for BAYC?
Crypto

Yuga Labs Sells Off Moonbirds IP to Double Down on Bored Apes and Otherside — Bullish Signal for BAYC?

May 30, 2025
Solana Co-Founder’s Data Leaked in Failed Extortion Stunt
Crypto

Solana Co-Founder’s Data Leaked in Failed Extortion Stunt

May 28, 2025
FIFA Teams Up With Avalanche To Launch Its Own Blockchain—Here’s What It Means
Crypto

FIFA Teams Up With Avalanche To Launch Its Own Blockchain—Here’s What It Means

May 24, 2025
Hester Peirce Slams SEC for Killing NFT Innovation: Confirms Many NFTs are NOT Securities
Crypto

Hester Peirce Slams SEC for Killing NFT Innovation: Confirms Many NFTs are NOT Securities

May 19, 2025
Conflicting Signals for AVAX: NFT Mania vs. Weak Demand
Crypto

Conflicting Signals for AVAX: NFT Mania vs. Weak Demand

May 17, 2025
JRNYERS on Cardano: A New Chapter Begins Right Now
Cardano

JRNYERS on Cardano: A New Chapter Begins Right Now

May 16, 2025
Load More

Related News

Stellar (XLM) Waking Up? Bull Flag Breakout Hints at $2+ Price Target

Stellar (XLM) Waking Up? Bull Flag Breakout Hints at $2+ Price Target

June 3, 2025
Sui Stumbles in Q1, But Holds On in the Rankings

Sui Stumbles in Q1, But Holds On in the Rankings

June 3, 2025
Tron Hits Record Transfer Volumes as Global Activity Soars

Tron Hits Record Transfer Volumes as Global Activity Soars

June 3, 2025
Dogecoin Dips but Hype and Hope Still Linger

Dogecoin Dips but Hype and Hope Still Linger

June 3, 2025
Solana Dips 15% but Long-Term Holders Signal Confidence

Solana Dips 15% but Long-Term Holders Signal Confidence

June 3, 2025
Discord Twitter Youtube TikTok Instagram

BLOCKNEWS.COM

BlockNews

BlockNews.com is your premier source for real-time cryptocurrency, blockchain, and financial market news.

Our mission is to deliver accurate, timely, and insightful information to help both seasoned investors and newcomers navigate the evolving digital economy.

With in-depth analysis, exclusive insights, and up-to-date news, BlockNews.com keeps you informed on the latest trends in crypto, DeFi, NFTs, tech, and beyond.

Stay ahead of the herd with BlockNews.com

RESOURCES

  • About
  • Contact Us
  • Terms and Conditions
  • Privacy Policy

POPULAR TOPICS

$ADA $XRP AI Avalanche Binance Bitcoin Bitcoin ETF blackrock Blockchain BTC Business Cardano China Coinbase Coinglass crypto cryptocurrency Crypto Exchange Crypto Regulation DeFi Dogecoin Donald Trump Elon Musk ETF eth ethereum Federal Reserve FTX grayscale Memecoin metaverse Microstrategy NFT NFTs PEPE ripple sec Shiba Inu Solana Stablecoin Technology twitter US Web3 xrp

GET QUICKER UPDATES ON X

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.

No Result
View All Result
  • Home
  • Crypto
  • Memecoins
  • Technology
  • Politics
  • Finance
  • NFT
  • DeFi
  • Opinion

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.