UN Links North Korea to $281m Crypto Exchange Heist

UN Links North Korea to $281m Crypto Exchange Heist

A cyber-attack on a cryptocurrency exchange last September which led to the theft of hundreds of millions of dollars in digital money has been blamed on North Korean actors.

A United Nations report to the UN Security Council seen by Reuters “strongly suggests” that hackers from the “hermit kingdom” were involved in the cyber-heist at KuCoin last September.

The attack led to the theft of $281m in cryptocurrency from the Singapore-headquartered firm, although CEO Johnny Lyu subsequently revealed that $204m had been recovered by the following week.

He also claimed at the time that investigators had unveiled the identities of the attackers, although he refused to go public with the information until the case is closed.

“Preliminary analysis, based on the attack vectors and subsequent efforts to launder the illicit proceeds, strongly suggests links to the DPRK,” the UN reportedly claimed, without naming KuCoin.

It said that Blockchain records revealed the same attackers were behind a separate $23m raid in October, according to the newswire.

The state actors apparently tried to bypass the larger cryptocurrency trading platforms which raised the alarm, by using exchanges that facilitate person-to-person currency swaps.

“According to sources familiar with both hacks, the attackers exploited ‘defi’ protocols – i.e., smart contracts that facilitate automated transactions,” the UN reportedly claimed.

The attack certainly fits the MO of North Korean state-backed operatives. In 2019, a UN report claimed that the Kim Jong-un regime had stolen as much as $2bn from banks and crypto exchanges for its weapons of mass destruction programs.

As an international pariah, opportunities to generate this kind of funding aren’t easy for the regime.

The report claimed cyber-attacks including cryptojacking can “generate income in ways that are harder to trace and subject to less government oversight and regulation than the traditional banking sector.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Cops Arrest Eight in US Celeb SIM Swap Case

UK Cops Arrest Eight in US Celeb SIM Swap Case

British law enforcers have arrested eight men on suspicion of running a SIM swapping ring targeting US celebrities and sports stars.

The National Crime Agency (NCA) led the investigation in the UK, working alongside agents from the US Secret Service, Homeland Security Investigations, the FBI and the Santa Clara California District Attorney’s Office.

SIM swapping is an increasingly popular way to hijack high-profile users’ social media and other accounts, and can also be used to steal cryptocurrency. Those behind the attacks typically either socially engineer carrier employees into porting the target’s number to a new SIM under their control, or use a malicious insider to do the same.

In this campaign, those arrested are suspected of targeting a range of “well-known influencers, sports stars, musicians and their families.” The NCA was tight-lipped on the identities of these victims.

However, it did reveal that the attackers used their access to victims’ phone numbers to takeover various accounts linked to their mobile devices and change the passwords. In such cases, reset codes are typically sent via SMS to the phone number linked to the account, landing it right in the lap of the cyber-criminal.

This enabled them to post on social media and send messages masquerading as the victims, and to steal money from bank and Bitcoin accounts and personal information including synced contacts.

The suspects arrested in England and Scotland were aged 18-26. Officers from Police Scotland, the Metropolitan Police Service, East Midlands and North East Special Operations Units, and the West Midlands Regional Organized Crime Unit supported the NCA.

Paul Creffield, head of operations at the NCA’s National Cyber Crime Unit, argued that the attackers singled out their victims as being lucrative targets.

“SIM swapping requires significant organization by a network of cyber-criminals, who each commit various types of criminality to achieve the desired outcome. In this case, those arrested face prosecution for offences under the Computer Misuse Act, as well as fraud and money laundering as well as extradition to the US for prosecution,” he added.

“As well as causing a lot of distress and disruption, we know they stole large sums from their victims, from either their bank accounts or Bitcoin wallets.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cloud Security Firm iboss Appoints New Senior Leaders

Cloud Security Firm iboss Appoints New Senior Leaders

Cloud security firm iboss has announced the appointment of two high-profile senior leaders as it looks to continue its rapid growth during the COVID-19 pandemic.

Eric Cornelius has become its new chief product officer, while Wallace Sann joins as senior vice-president of technical operations, with the pair tasked with increasing adoption of iboss’ Secure Access Service Edge (SASE) and zero-trust (ZTNA) solutions. Cornelius will oversee the strategy and development of the company’s security products and Sann will help grow its marketing plan and enhance user experience.

Cornelius and Sann come with a wealth of experience in the IT security industry. Cornelius’ most recent role was chief product architect at BlackBerry and he has also served as chief technology officer at Cylance. He has additionally held critical security positions in the US government and Army in a career spanning nearly two decades in the cybersecurity and computer science fields.

Sann was most recently vice-president of worldwide sales engineering and enablement at IronNet Cybersecurity, and before that, VP of global systems engineering and government CTO at Forescout Technologies. In total, he has over 20 years of experience in building, leading and developing marketing teams which have an emphasis on customer experience.

The announcement comes shortly after iboss raised $145m in a funding round, which will help the rapid growth of the company amid increased adoption of cloud services to support the shift to home working.

Commenting on the news, iboss CEO Paul Martini, said: “Having Eric and Wallace join our team is truly a one-two punch. Eric’s experience developing and overseeing the strategy behind best-in-class cybersecurity solutions and Wallace’s proven ability to successfully scale innovative organizations further strengthens our competitive advantage. The future of security is in the cloud and our new team members will help us reach and protect even more of the world’s biggest and best companies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk