North Korean hackers are using a new malware variant called “Durian” to conduct attacks on South Korean cryptocurrency companies.
According to a May 9 threat report from cybersecurity company Kaspersky, North Korean hacker group Kimsuky used new malware in a series of targeted attacks on at least two cryptocurrency companies. dead until now.
This was done through a “persistent” attack that exploited legitimate security software used exclusively by cryptocurrency companies in South Korea.

The Durian malware previously acted as an installer that deployed a continuous stream of malware that included a backdoor called “AppleSeed,” a custom proxy tool called LazyLoad, and legitimate tools other like Chrome Remote Desktop.
“Durian boasts comprehensive backdoor functionality, allowing execution of sent commands, download of additional files, and extraction of files,” Kaspersky wrote.
Additionally, Kaspersky notes that LazyLoad is also used by Andariel, a subgroup within the North Korean hacking conglomerate Lazarus Group – something that suggests a “tenuous” connection between Kimsuky and the more notorious hacking group.
First emerging in 2009, Lazarus has established itself as one of the most notorious crypto hacker groups. On April 29, independent blockchain detective ZachXBT revealed that the Lazarus group successfully laundered over $200 million in illegal cryptocurrency between 2020 and 2023.
In total, the Lazarus Group allegedly stole more than $3 billion in Cryptoasset in the six years leading up to 2023.
Since 2017, North Korea has significantly increased its focus on the cryptocurrency industry, stealing an estimated $3 billion worth of cryptocurrency. pic.twitter.com/cES9gq2AK3
— Recorded Future (@RecordedFuture) November 30, 2023
According to a December 28 report by Immunefi, Lazarus is believed to have stolen more than 17% – a little more than $309 million – of the total amount stolen in 2023. Over the course of 2023, more than 1.8 billion Cryptocurrency dollars have been lost due to hacking and mining.
Please continue to follow Coin Moi to stay updated with the latest news in the market!
The article North Korean Hackers Deploy “Durian” Malware, Targeting Cryptocurrency Companies appeared first on CoinMoi .




