skip to Main Content
bitcoin
Bitcoin (BTC) $ 75,894.33 0.23%
vested-xor
Vested XOR (VXOR) $ 3,405.08 99,999.99%
ethereum
Ethereum (ETH) $ 2,879.30 5.35%
tether
Tether (USDT) $ 1.00 0.06%
solana
Solana (SOL) $ 195.05 3.95%
bnb
BNB (BNB) $ 597.10 0.62%
usd-coin
USDC (USDC) $ 0.999897 0.04%
xrp
XRP (XRP) $ 0.552971 1.50%
staked-ether
Lido Staked Ether (STETH) $ 2,877.90 5.31%
dogecoin
Dogecoin (DOGE) $ 0.191546 2.72%

North Korea Hackers Likely Exploit Cloud Mining to Launder Stolen Crypto, Research Shows

Consensus 2023 Logo

Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

CoinDesk - Unknown

Eliza Gkritsi is CoinDesk’s crypto mining reporter based in Asia.

Consensus 2023 Logo

Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

North Korean hacker group APT43 probably uses cloud mining services to launder stolen crypto, according to research by Google-owned cybersecurity firm Mandiant.

Cloud mining services own and operate infrastructure and rent out hashrate to users. Hashrate is a measure of the total amount of computer processing power to secure a cryptocurrency. APT43 uses stolen cryptocurrency to pay for these services and receives crypto not associated with the crime to wallets of its choice, according to the report released on Tuesday.

The group is “moderately sophisticated” and supports the strategic and nuclear objectives of the North Korean regime, according to Mandiant. It uses the proceeds from cybercrime to fund its operations, which target South Korean and U.S. government organizations, academics and think tanks focused on the geopolitics of the Korean peninsula, the report said.

To acquire the crypto, APT43 steals credentials, often by phishing attacks. That is, it creates legitimate-looking websites – for example, a site masquerading as a crypto exchange – and persuades unsuspecting users to reveal personal information.

North Korean hackers have been increasingly including crypto in their operations, often in high-profile digital heists like the $100 million Horizon Bridge theft, according to the FBI. Authorities around the world, particularly in the U.S. and South Korea, are trying to combat the threat.

Mandiant was acquired by Google and integrated into its cloud service in September 2022.

Edited by Sheldon Reback.

DISCLOSURE

Please note that our

privacy policy,

terms of use,

cookies,

and

do not sell my personal information

has been updated

.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a

strict set of editorial policies.

CoinDesk is an independent operating subsidiary of

Digital Currency Group,

which invests in

cryptocurrencies

and blockchain

startups.

As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of

stock appreciation rights,

which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG

.

CoinDesk - Unknown

Eliza Gkritsi is CoinDesk’s crypto mining reporter based in Asia.


Learn more about Consensus 2023, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.


CoinDesk - Unknown

Eliza Gkritsi is CoinDesk’s crypto mining reporter based in Asia.

Loading data ...
Comparison
View chart compare
View table compare
Back To Top