Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

HYPE ETFs quietly pulled $161M in one month as Wall Street buys crypto’s on-chain exchange bet

June 15, 2026

CLARITY Act Gets New Push as Senator Ties Crypto Rules to US Dollar Power

June 15, 2026

Spot Bitcoin ETFs Snap Five-Day Outflow Streak With $85.8 Mi

June 15, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Lazarus Rises Again with Aggressive Bitcoin-Stealing Campaign
Lazarus Rises Again with Aggressive Bitcoin-Stealing Campaign
Security and Privacy

Lazarus Rises Again with Aggressive Bitcoin-Stealing Campaign

September 6, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

An aggressive Bitcoin-stealing phishing campaign mounted by the international cybercrime group Lazarus and using sophisticated, brand-new malware has been uncovered.

McAfee Advanced Threat Research (ATR) analysts discovered the campaign, dubbed HaoBao. It resumes Lazarus’ previous phishing email efforts, which used lures aimed at employee recruitment and targeted US defense contractors, the energy sector and financial institutions, including cryptocurrency exchanges. The objective was to gain access to the target’s environment and obtain key military program insight or steal money. Those efforts ceased in October 2017 but are ramping up again; and this time, the targeted emails are aimed at Bitcoin users and global financial organizations.

In mid-January, McAfee discovered a malicious document masquerading as a job recruitment ad for a “Business Development Executive” for a large, multinational bank located in Hong Kong. The document was distributed via a Dropbox account. When recipients open the malicious documents attached to the emails, they are persuaded to enable content through a notification claiming the document was created in an earlier version of Microsoft Word. The malicious documents then launch an implant on the recipients’ system via a Visual Basic macro.

The malware scans for Bitcoin activity and then establishes a secondary implant for long-term data gathering. The interesting thing is that the implants have never before been seen, and indicate a newly sophisticated level of attack.

“This is the mark of a new campaign, though it utilizes techniques, tactics and procedures observed in 2017,” explained McAfee analyst Ryan Sherstobitoff in an analysis. “McAfee ATR analysis finds the dropped implants…have not been used in previous Lazarus campaigns from 2017. Furthermore, this campaign deploys a one-time data gathering implant that relies upon downloading a second stage to gain persistence.”

See also  Lazarus Group Targets macOS in Supply Chain Assault

He added that there’s no indication that Lazarus won’t continue its efforts.

“Despite a short pause in similar operations, the Lazarus group targets cryptocurrency and financial organizations,” said Sherstobitoff. “Furthermore, we have observed an increased usage of limited data gathering modules to quickly identify targets for further attacks. This campaign is tailored to identifying those who are running Bitcoin related software through specific system scans.”

Source link

Aggressive BitcoinStealing campaign Lazarus rises
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

UK crypto advocates launch campaign against banks blocking exchange transfers

June 12, 2026

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Coinbase-backed Stand With Crypto calls on members to campaign against banks blocking digital asset transactions

June 12, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

A New Era of User-Friendly Blockchain Transactions

January 25, 2024

ALGO bounces back but retains its bearish structure

September 23, 2023

Dogecoin Up by Nearly 15% in 24 Hours After Coinbase Announces Plans To Launch DOGE Futures Trading

March 21, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

HYPE ETFs quietly pulled $161M in one month as Wall Street buys crypto’s on-chain exchange bet

June 15, 2026

CLARITY Act Gets New Push as Senator Ties Crypto Rules to US Dollar Power

June 15, 2026

Spot Bitcoin ETFs Snap Five-Day Outflow Streak With $85.8 Mi

June 15, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$65,388.001.22%
  • ethereumEthereum(ETH)$1,711.181.52%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$613.350.56%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • rippleXRP(XRP)$1.182.14%
  • solanaSolana(SOL)$70.772.62%
  • tronTRON(TRX)$0.3200141.32%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • HyperliquidHyperliquid(HYPE)$63.484.04%