Breaking
March 19, 2025

North Korean Hackers Transfer $750,000 in ETH to Tornado Cash, Deploy New Malware Oliver Dale | usagoldmines.com

TLDR

  • Lazarus Group deposited 400 ETH (~$750,000) to Tornado Cash on March 13, 2025
  • The North Korean hackers were linked to February’s $1.4 billion Bybit hack
  • Six new malicious packages called “BeaverTail” were deployed on NPM to steal credentials and crypto wallet data
  • The malware targets Chrome, Brave, Firefox browsers, and Solana/Exodus wallets
  • North Korean hackers stole over $1.3 billion in crypto across 47 attacks in 2024, double the amount stolen in 2023

North Korea’s Lazarus Group has moved 400 Ethereum (ETH) worth approximately $750,000 to Tornado Cash mixing service on March 13, 2025. Blockchain security firm CertiK detected the transaction and traced it back to the group’s activity on the Bitcoin network.

The Lazarus Group has been connected to many large crypto hacks. They were responsible for the $1.4 billion Bybit exchange hack in February 2025. They were also linked to the $29 million Phemex exchange hack in January.

After the Bybit hack, the group used various methods to hide the stolen funds. They used decentralized exchanges like THORChain that don’t require identity checks. Reports show that around $2.91 billion was moved through THORChain in just five days.

This made it much harder for authorities to track and recover the stolen money. The group has become known for using mixing services and other techniques to launder cryptocurrency after their attacks.

The hacking group has also started a new malware campaign. On March 11, security firm Socket reported that the group had launched six new malicious software packages on the Node Package Manager (NPM) platform.

NPM is a tool used by developers to manage and install JavaScript packages for their projects. The malware, including a package called “BeaverTail,” is designed to steal credentials and crypto wallet data.

Typosquatting

The hackers use a trick called typosquatting. This involves slightly changing the names of trusted software to fool developers into downloading the malicious versions. For example, they might create packages with names very similar to legitimate and widely used libraries.

The malware targets stored credentials in Chrome, Brave, and Firefox browsers. It also specifically looks for data from Solana and Exodus cryptocurrency wallets.

Socket researchers noted that while it’s challenging to attribute this attack with absolute certainty, “the tactics, techniques, and procedures observed in this npm attack closely align with Lazarus’s known operations.”

Fake Zoom Calls

The North Korean hackers have also tried to trick crypto founders with fake Zoom calls. They pose as venture capitalists and send fake meeting links. When they claim to have audio issues, they send victims a supposed fix that actually installs malware.

Security researchers have reported that several crypto founders have encountered these scams. The approach shows how the group adapts their methods to target specific people in the cryptocurrency industry.

The Lazarus Group has a long history of crypto attacks. They were behind the $600 million Ronin network hack in 2022, one of the largest crypto thefts in history.

According to data from Chainalysis, North Korean hackers stole over $1.3 billion in cryptocurrency across 47 different attacks in 2024. This amount is more than double what they stole in 2023.

The increase in both the number and size of attacks shows that North Korean hacking operations are growing. Cybersecurity experts warn that the group continues to develop new methods to steal and launder digital assets.

CertiK and other security firms continue to monitor blockchain transactions to detect suspicious activity. Their work helps exchanges and users be more aware of potential threats.

As these attacks continue, cryptocurrency exchanges and platforms are working to improve their security measures. However, the Lazarus Group’s techniques keep evolving, creating an ongoing challenge for the crypto industry.

The post North Korean Hackers Transfer $750,000 in ETH to Tornado Cash, Deploy New Malware appeared first on Blockonomi.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Don’t Take the Bait: Coinbase & Gemini Exchange Users Targeted by Phishing Attack Oliver Dale | ...

Dark Storm Hacktivist Group Claims Responsibility for X Platform Disruption Oliver Dale | usagoldmin...

Russian Cybercrime Group Uses Fake Job Interviews and ‘GrassCall’ App to Drain Crypto Wallets Nichol...

World Network in Philippines to Battle Scams with Human ID Nicholas Say | usagoldmines.com

Kaspersky Uncovers Mobile Malware Targeting Crypto Users on iOS and Android Oliver Dale | usagoldmin...

Warning: The Telegram Verification Bot Could Empty Your Crypto Wallet Oliver Dale | usagoldmines.com

Animoca Brands Co-founder Yat Siu’s X Account Hacked to Promote Fake Solana Memecoin Nicholas Say | ...

Hyperliquid Token Falls 21% Following North Korean Hacking Concerns Oliver Dale | usagoldmines.com

LastPass Hackers Steal $5.36M From Users Days Before Holidays Nicholas Say | usagoldmines.com

Ledger Hardware Wallet User Reports $2.5M Digital Asset Loss Oliver Dale | usagoldmines.com

Google’s Willow Quantum Chip: A Step Forward in Computing, But Bitcoin Remains Secure Oliver Dale | ...

Cardano Foundation X Account Compromised, False SEC Claims Circulate Oliver Dale | usagoldmines.com

Japanese Exchange DMM Bitcoin to Cease Operations After $320 Million Hack Nicholas Say | usagoldmine...

Sumsub Partners with Elliptic to Strengthen Crypto Fraud Prevention and Compliance Tools Oliver Dale...

Crypto Platform’s $12M Nightmare: Inside the Polter Finance Hack Oliver Dale | usagoldmines.com

Phantom Wallet iOS Update Error Results in User Fund Access Problems Oliver Dale | usagoldmines.com

X Account Hack Forces Terminal of Truths Developer to Relocate $1.8M in Crypto Oliver Dale | usagold...

Radiant Capital Hit by $50M Blockchain Security Breach Nicholas Say | usagoldmines.com

US, UK, and Australia Target Russian Cybercrime Syndicate | usagoldmines.com

LEGO Website Experiences Brief Hack Promoting Fake Cryptocurrency | usagoldmines.com

Google Play Hosts Crypto Wallet Drainer for Five Months, $70,000 Stolen | usagoldmines.com

Bedrock Protocol Reports $2M Exploit: Reimbursement Plan in Progress | usagoldmines.com

MEV Bot’s $12 Million Flash Loan Yields Meager $20 Profit | usagoldmines.com

Binance Collaborates with Indian Authorities to Uncover $47.6M Gaming Scam | usagoldmines.com

FBI Warns of “Pig Butchering” Schemes Targeting Crypto Investors | usagoldmines.com

Binance Investigates and Refutes Alleged 12.8 Million User Data Leak | usagoldmines.com

Sam Altman’s Company Falls Victim to Online Crypto Fraud | usagoldmines.com

BingX Exchange Hacked: $43 Million Stolen, Users to be Reimbursed | usagoldmines.com

Truflation Reports $5 Million Loss in Malware Attack on Blockchain Platform | usagoldmines.com

Leave a Reply