
Bitrefill, a platform for buying gift cards with cryptocurrency, suspects that North Korean hackers from the Bluenoroff group were behind the cyberattack it experienced earlier this month.
The company’s investigation uncovered evidence mirroring past attacks linked to the North Korean group, including similar methods, malicious software, and IP and email addresses.
“Based on our investigation, which considered things like how the attack was carried out, what malware was used, blockchain analysis, and reused IP and email addresses, we see strong similarities between this attack and previous cyberattacks by the North Korean Lazarus / Bluenoroff group targeting crypto firms,” Bitrefill said.
Bitrefill is an online store where customers can use cryptocurrency to purchase gift cards for various retailers in 150 countries. These gift cards can be used for a wide range of items, including clothes, food, healthcare products, and to pay for bills, services, gas, transportation, and electronics.
The platform supports over 600 mobile carriers and thousands of brands globally.
On March 1st, Bitrefill reported technical problems affecting its website and app. The next day, the company revealed a security issue and took all services offline.
Although user funds were unaffected, the restoration of all services is still ongoing.
The security incident was detected after Bitrefill noticed unusual purchasing patterns from suppliers, exploitation of gift card inventory and distribution, and withdrawals from some active cryptocurrency wallets.
The investigation revealed that the attack originated from a compromised employee’s laptop.
The attackers stole old login details and used them to gain access to a snapshot containing sensitive production information, enabling them to escalate their access to Bitrefill’s larger infrastructure, including parts of the database and some cryptocurrency wallets.
About 18,500 purchase records, including customer email addresses, IP addresses, and cryptocurrency payment addresses, were exposed. For a smaller subset of 1,000 purchases, customer names were also compromised.
While this data is stored encrypted, Bitrefill acknowledges that the attackers may have also obtained the keys to decrypt it.
Bitrefill describes this as the most significant cyberattack in its ten-year history but states that the business sustained it with minimal financial impact, which it can cover with their own funds.
Bitrefill believes the attackers primary intention was to steal cryptocurrency and gift card balances, not customer information.
BlueNoroff, also known as APT38, is a subgroup of the Lazarus group and has been operating since at least 2014. It traditionally targets financial institutions, but recently it has been more focused on the cryptocurrency industry, with the goal of stealing crypto.
Bitrefill describes this as the most significant cyberattack in its ten-year history but states that the business sustained it with minimal financial impact, which it can cover with their own funds.
The company is improving security measures such as security audits, pen-testing, strengthening who has access, better monitoring tools, and better response mechanisms.
Currently, the majority of Bitrefill’s services are operational, and customers only need to treat communications with additional caution.
#attributes #bitrefill #cyberattack #group #hacking #korean #lazarus #news #north #organization — News
© Bulletproof Servers. All rights reserved.