pwshub.com

Feds seize tiny sliver of crypto stolen by Lazarus Group

The US government is attempting to claw back more than $2.67 million stolen by North Korea's Lazarus Group, filing two lawsuits to force the forfeiture of millions in Tether and Bitcoin.

The first lawsuit stems from the 2022 Deribit hack, during which the North Korean criminals drained about $28 million from the crypto exchange's hot wallet. The crooks then laundered the funds through virtual currency exchanges, the Tornado Cash mixer and virtual currency bridges in an attempt to cover their tracks.

"Although mixing services are used to obfuscate the trail of funds, law enforcement can sometimes trace the funds in and out – as they did here," according to the court documents [PDF].

The feds ultimately recovered about $1.7 million worth of Tether in five frozen wallets.

About a year after the Lazarus Group allegedly Deribit, they supposedly stole another $41 million from Stake.com – an online casino and gambling site. That heist is the subject of the second lawsuit.

After breaking into Stake.com's computer systems and stealing roughly tens of millions in virtual currency, "the North Koreans and their money laundering co-conspirators transferred the stolen funds through virtual currency bridges, several BTC addresses, and virtual currency mixers before consolidating funds and depositing the virtual currency at different virtual currency exchanges," the forfeiture action notes [PDF] explain.

In this case, the Lazarus Group moved the stolen BTC through Bitcoin mixers Sinbad and Yonmix. Sinbad has since been sanctioned by the US government for laundering millions for the North Korean heists.

  • North Korean chap charged for attacks on US hospitals, military, NASA – and even China
  • Baddies hijack Korean ERP vendor's update systems to spew malware
  • New Nork-ish cyberespionage outfit uncovered after three years
  • Crypto wallet providers urged to rethink security as criminals drain them of millions

While law enforcement was able to freeze assets from seven transactions, "the North Koreans were able to transfer the majority of the stolen funds to the BTC blockchain," according to the court documents.

The FBI was able to recover an additional .099 BTC, or about $6,270, from an eighth transaction. Then, on February 9 the Department of Justice served a federal seizure warrant for those funds, which were transferred to the government.

These, according to the lawsuits, are just a couple of the digital intrusions that the feds have linked to Kim Jong Un's crew. As explained in the court documents:

This same group of notorious crypto crooks is believed to be responsible for the $234.9 million WazirX exchange hack. ®

Source: theregister.com

Related stories
1 month ago - Hidden cargo — US seizes 350 sites that masked gun part imports from China as toys, jewelry. ...
1 week ago - Winter is coming The US Department of Justice and Microsoft have seized 107 websites used by Russian cyberspies in a phishing campaign to steal sensitive information from US government agencies, think tanks, and other victims.…
1 month ago - Illegal goods allegedly shipped to the US labeled as toys or jewels The US Attorney's Office in the District of Massachusetts has seized more than 350 internet domains allegedly used by Chinese outfits to sell US residents kits that...
2 weeks ago - With 14 serious security flaws found, what a gift for spies and crooks Fourteen bugs in DrayTek routers — including one critical remote-code-execution flaw that received a perfect 10 out of 10 CVSS severity rating — could be abused by...
1 month ago - Russia has seemingly decided who it wants Putin the Oval Office The Biden administration on Wednesday seized 32 websites and charged two employees of a state-owned media outlet connected to a $10 million scheme to distribute pro-Kremlin...
Other stories
3 hours ago - A recently removed online store listing claimed that Microsoft is preparing a new Surface laptop featuring Intel's recently introduced Lunar Lake Core 200 architecture. Sources from Windows Central corroborated this information, claiming...
7 hours ago - Resolves allegations it improperly stored screenshots containing PII that were later snaffled A US government contractor will settle claims it violated cyber security rules prior to a breach that compromised Medicare beneficiaries'...
8 hours ago - The Justice Department announced the defense contractor has agreed to three years of independent monitoring after violating the Foreign Corrupt Practices Act.
8 hours ago - Hospitals, government agencies, and a large roster of tech companies all targeted.
8 hours ago - “Tsavo Man-Eaters” killed dozens of people in late 1890s, including Kenya-Uganda Railway workers.