CryptoMediaClub
Thursday, November 13, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home Blockchain

Lazarus used ‘Kandykorn’ malware in attempt to compromise exchange — Elastic

02.11.2023
A A
0
126
VIEWS
ShareShare

Lazarus Group used a new form of malware in an attempt to compromise a crypto exchange, according to an Oct. 31 report from Elastic Security Labs.

Elastic has named the new malware “Kandykorn” and the loader program that loads it into memory “Sugarload,” as the loader file has a novel “.sld” extension in its name. Elastic did not name the exchange that was targeted.

Crypto exchanges have suffered a rash of private-key hacks in 2023, most of which have been traced to the North Korean cybercrime enterprise Lazarus Group.

Kandykorn infection process. Source: Elastic Security Labs

According to Elastic, the attack began when Lazarus members posed as blockchain engineers and targeted engineers from the unnamed crypto exchange. The attackers made contact on Discord, claiming they had designed a profitable arbitrage bot that could profit from discrepancies between the prices of cryptocurrencies on different exchanges.

The attackers convinced the engineers to download this “bot.” The files in the program’s ZIP folder had disguised names like “config.py” and “pricetable.py” that made it appear to be an arbitrage bot.

Once the engineers ran the program, it executed a “Main.py” file that ran some ordinary programs as well as a malicious file called “Watcher.py.” Watcher.py established a connection to a remote Google Drive account and began downloading content from it to another file named testSpeed.py. The malicious program then ran testSpeed.py a single time before deleting it in order to cover its tracks.

During the single-time execution of testSpeed.py, the program downloaded more content and eventually executed a file that Elastic calls “Sugarloader.” This file was obfuscated using a “binary packer,” Elastic stated, allowing it to bypass most malware detection programs. However, they were able to discover it by forcing the program to stop after its initialization functions had been called, then snapshotting the process’ virtual memory.

According to Elastic, it ran VirusTotal malware detection on Sugarloader, and the detector declared that the file was not malicious.

Related: Crypto firms beware: Lazarus’ new malware can now bypass detection

Once Sugarloader was downloaded onto the computer, it connected to a remote server and downloaded Kandykorn directly into the device’s memory. Kandykorn contains numerous functions that can be used by the remote server to perform various malicious activities. For example, the command “0xD3” can be used to list the contents of a directory on the victim’s computer, and “resp_file_down” can be used to transfer any of the victim’s files to the attacker’s computer.

Elastic believes that the attack occurred in April 2023. It claims that the program is probably still being used to perform attacks today, stating:

“This threat is still active and the tools and techniques are being continuously developed.”

Centralized crypto exchanges and apps suffered a rash of attacks in 2023. Alphapo, CoinsPaid, Atomic Wallet, Coinex, Stake and others have been victims of these attacks, most of which seem to have involved the attacker stealing a private key from the victim’s device and using it to transfer customers’ cryptocurrency to the attacker’s address.

The United States Federal Bureau of Investigation has accused the Lazarus Group of being behind the Coinex hack, as well as performing the Stake attack and others.

Share10Tweet6ShareSharePin2

Related Posts

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei
Blockchain

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei

18.07.2025
0

Skip to content

Read moreDetails
Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

17.07.2025
LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

14.07.2025
Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

14.07.2025
Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

08.07.2025
Load More
Next Post

Bitcoin Dominance Is Still In Its Expansion Phase: Glassnode

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Paraguay Launches Tokenized Innovation Hub on Polkadot

Paraguay Launches Tokenized Innovation Hub on Polkadot

2 months ago
Ethereum burns $2.5B worth of ETH since merge as supply drops to 18 month low

Ethereum burns $2.5B worth of ETH since merge as supply drops to 18 month low

2 years ago
How decentralization can mitigate ‘dystopic’ artificial intelligence risks — SingularityNET exec

How decentralization can mitigate ‘dystopic’ artificial intelligence risks — SingularityNET exec

2 years ago
Cardano Light Wallet ‘Eternl’ All Set to Release New Enhanced Version

Cardano Light Wallet ‘Eternl’ All Set to Release New Enhanced Version

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Fraudsters Exploit Australia’s Cybercrime Portal to Impersonate Police and Steal Crypto

[LIVE] Crypto News Today: Latest Updates for Nov. 13, 2025 – RWA and NFT Tokens Lead Market Gains as Bitcoin Slips Below $103K

Bitcoin Price Prediction: Is BTC’s $104K Breakout the Calm Before a Massive Year-End Rally?

Trump Price Prediction: Whale Orders Surge, Momentum Builds – Could TRUMP Be the Next 10x Play?

The SEC Is Considering Establishing A ‘Token Taxonomy,’ Chair Paul Atkins Says

XRP Social Buzz Surges On ETF Chatter, Latest Data Shows

Trending

Bitcoin flash-crashed to $100k — then roared back. Here’s what really happened behind the $610M liquidations
Analysis

Bitcoin flash-crashed to $100k — then roared back. Here’s what really happened behind the $610M liquidations

13.11.2025
0

Bitcoin fell to $100,800 on November 12, down 4.2% in 24 hours, as the broader crypto market...

Bitcoin Price Prediction: Why Early Bitcoin Millionaires Are Suddenly Selling – And What It Means for The Whole Crypto Market

Bitcoin Price Prediction: Why Early Bitcoin Millionaires Are Suddenly Selling – And What It Means for The Whole Crypto Market

13.11.2025
US Treasury Buys Back $142M in Debt — Here’s What It Means for Crypto

US Treasury Buys Back $142M in Debt — Here’s What It Means for Crypto

13.11.2025
Fraudsters Exploit Australia’s Cybercrime Portal to Impersonate Police and Steal Crypto

Fraudsters Exploit Australia’s Cybercrime Portal to Impersonate Police and Steal Crypto

13.11.2025
[LIVE] Crypto News Today: Latest Updates for Nov. 13, 2025 – RWA and NFT Tokens Lead Market Gains as Bitcoin Slips Below $103K

[LIVE] Crypto News Today: Latest Updates for Nov. 13, 2025 – RWA and NFT Tokens Lead Market Gains as Bitcoin Slips Below $103K

13.11.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz