North Korean Hackers Use New Malware “Durian” to Target South Korean Crypto Firms
A recent report from cybersecurity firm Kaspersky reveals that North Korean hackers, specifically the Kimsuky group, are using a notable new malware variant called “Durian” to carry out attacks on South Korean cryptocurrency companies. The attacks, identified as persistent, exploit legitimate security software used only by crypto firms in South Korea.
Previously unknown to the cybersecurity community, the Durian malware functions as an installer that distributes a number of malware, including a backdoor called “AppleSeed”, a special proxy tool called LazyLoad, and other legitimate tools such as Chrome Remote Desktop sees. Kaspersky states that Durian has extensive backdoor functionality that allows the execution of transmitted commands, the downloading of additional files and the exfiltration of data.
Interestingly, Kaspersky also discovered that LazyLoad, the proxy tool used by Durian, was previously associated with Andariel, a subgroup of the North Korean hacking consortium Lazarus Group. This suggests a potential connection between Kimsuky and the more notorious Lazarus Group.
In 2023 alone, Lazarus was responsible for theft of over $309 million; this accounted for approximately 17% of the total funds stolen that year. According to a report by cybersecurity company Immunefi, cryptocurrencies worth more than $1.8 billion have fallen victim to hacks and exploits throughout 2023.