Vote for Cryptopolitan on Binance Square Creator Awards 2024. Click here to support our content!

Hacking group CryptoCore has stolen $200M from exchange employees

In this post:

CryptoCore has swindled more than $200 million from cryptocurrency exchanges since 2018.

According to a report by ClearSky cybersecurity, the group targets cryptocurrency exchange employees and executives with phishing scams. The group is known as CryptoCore but also notorious under the aliases of “Dangerous Password” “Leery Turtle.”

CryptoCore hackers

CryptoCore scammers fool people working at exchanges by impersonating high-ranking employees of the same exchange to access their credentials. The hackers ask for access to the victim’s password manager account from where they can get their financial credentials.

The scammers use the passwords to steal the victim’s assets and all data that can be used to target other victims.

The report stated that the attackers’ main objective is to access the exchange’s wallets including the corporate wallets and wallets owned by employees. The attackers begin with an “extensive reconnaissance phase” against the company and all personnel working with the exchange.

Targets and method of operation

CryptoCore has been targeting exchanges in the US and Japan. The group has stolen more than $200 million worth of cryptocurrencies through phishing scams.

Read Also  Post Twitter hack, Pentagon too wants crypto surveillance application

The group first conducts thorough research about its target exchange then impersonates specific entities by using similar domain names.

The group infects the victim’s device by sending them files that require a supposed password to open. Once run, the files install malware on the device that searches the password managers for data. The malware then infects the exchange’s network to search for passwords.

Once the group gains access to wallets, the funds are moved to the wallets they control. While it is unclear where the group operates from, ClearSky believes that the group is based in East Europe. Many hacking groups targetting crypto-related businesses are reported to be working from North Korea.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Share link:

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Editor's choice

Loading Editor's Choice articles...

Stay on top of crypto news, get daily updates in your inbox

Most read

Loading Most Read articles...
Subscribe to CryptoPolitan