February 6, 2020

Chainalysis told how North Korean hackers hacked DragonEx crypto exchange

North Korean cybercriminals are more likely to be responsible for last year's hacking of the Singapore DragonEx cryptocurrency exchange, writes the Korea Herald, citing an investigation by Chainalysis.


Lazarus hacker group created a fictitious company to promote an automated trading bot, including a fake website and employees in this scheme, and contacted key DragonEx representatives.

DragonEx employees downloaded a free trial version of the software they proposed, thus giving hackers access to their computers. As a result, about $ 7 million in bitcoins, XRP, Litecoin and other cryptocurrencies was stolen from the exchange.

Chainalysis noted that the strategy used by Lazarus demonstrates the high level of preparation of the group, which goes beyond the usual "e-mails and small-scale sites" for phishing.

“DragonEx hack demonstrates the deep understanding of the cryptocurrency ecosystem that is necessary in order to successfully impersonate its full members,” the company said.

According to analysts, Lazarus are different from other hacker groups, as they are mainly driven by financial incentives, while others still usually try to wreak havoc in the process.