The Lazarus Group, a North Korean government-sponsored hacking organization, is reportedly ramping up its phishing attacks against the cryptocurrency community via Telegram.
According to blockchain security firm SlowMist, the group's new method involves impersonating reputable venture capital figures from Archax, HashKey and Gumi Cryptos to attract cryptocurrency teams with enticing investment offers.
In this method, the hacker gains their trust by sending messages to their victims and then leads them to malicious scripts for phishing attacks under the pretext of attending a meeting.


Beginning
Blockchain security firm Slomyst has identified a specific IP address, 104.168.137.21, associated with these attacks and is warning users to be alert to potential threats.
It is estimated that North Korean hackers have stolen more than $3 billion in the past five years, which have been used to finance North Korea's weapons program.
Cryptoslit
RCO NEWS