BitMEX uncovers phishing attacks by North Korean hacker Lazarus Group, reveals its real IP and work patterns

PANews reported on June 3 that BitMEX recently disclosed that its security team successfully uncovered an attack led by the North Korean-backed Lazarus Group. Hackers attempted to lure employees to access GitHub projects containing malicious code on the grounds of "Web3 NFT platform collaboration." The investigation found that the malicious program recorded the victim's device information through the Supabase database, and accidentally leaked the attacker's real IP due to incorrect permission configuration. One of the IPs came from the China Mobile network in Jiaxing, China, exposing his "Victor" identity operation error. The team also tracked the attacker's daily routine and VPN usage information, and disclosed multiple IoC indicators for community reference.

Share to:

Author: PA一线

This content is for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
23 minute ago
3 hour ago
6 hour ago
8 hour ago
9 hour ago
2025-12-12 15:30

Popular Articles

Industry News
Market Trends
Curated Readings

Curated Series

App内阅读