Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

KelpDAO commits 2,000 ETH to DeFi united recovery fund for rsETH restoration

May 3, 2026

Steel Power Unveiled: Is SteelPower Male Enhancement Formula Legit? Read Steel Power Supplement Report!

May 2, 2026

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»North Korean Group TA444 Shows ‘Startup’ Culture, Tries Numerous Infection Methods
North Korean Group TA444 Shows 'Startup' Culture, Tries Numerous Infection Methods
Security

North Korean Group TA444 Shows ‘Startup’ Culture, Tries Numerous Infection Methods

October 11, 2023No Comments2 Mins Read

A previously unknown, financially motivated North Korea state-sponsored threat actor has been observed testing several infection methods in the wild while adhering to a ‘startup’ culture mentality.

The findings come from security researchers at Proofpoint, who called the group TA444 and said it has been active in its current form of targeting cryptocurrency exchanges since at least 2017.

According to an advisory published earlier today, the group then adopted an upstart mentality at the end of 2022.

“Equally as surprising as the variance in delivery methods is the lack of a consistent payload at the end of the delivery chains,” reads the advisory from senior threat researcher Greg Lesnewich and the Proofpoint threat research team.

“When other financially-oriented threat actors test delivery methods, they tend to load their traditional payloads; this is not the case with TA444. This suggests […] an embedded, or at least a devoted, malware development element alongside TA444 operators.”

Further, Proofpoint said they noticed a complete marketing strategy designed by TA444 to increase its annual recurring revenue (ARR) potential.

“It all starts with crafting lure content that may be of interest or necessity to the target. These can include analyses of cryptocurrency blockchains, job opportunities at prestigious firms, or salary adjustments.”

In terms of tools used during the attacks, Lesnewich wrote TA444 used “an impressive set of post-exploitation backdoors in its history.”

The list includes msoRAT, Cardinal, the Rantankba suite, Cheesetray and Dyepack, alongside passive backdoors, virtualized listeners and browser extensions to facilitate theft.

“While we may poke fun at its broad campaigns and ease of clustering, TA444 is an astute and capable adversary that is willing and able to defraud victims for hundreds of millions of dollars,” Proofpoint wrote.

See also  KelpDAO Hack 'Contagion' Triggers Worst DeFi Liquidity Crunch Since 2024

“TA444 and related clusters are assessed to have stolen nearly $400m […] worth of cryptocurrency and related assets in 2021. In 2022, the group surpassed that value in a single heist worth over $500m, gathering more than $1bn during 2022.”

The Proofpoint report comes days after the US Federal Bureau of Investigation (FBI) confirmed that North Korea’s Lazarus Group was behind the $100m theft from cryptocurrency firm Harmony.

Source link

Culture Group Infection Korean Methods North Numerous Shows Startup TA444

Related Posts

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026
Top Posts

UnitedHealth: Top-Notch Healthcare Leader – But Its Best Days Could Be Over

October 10, 2023

Zelensky Goes Full “Lord Of War” As Ukraine Pitches Battle-Tested War Robots To Highest Bidder

April 16, 2026

Bitcoin Lightning Network Developer Resigns Over Security Fears

October 22, 2023

Type above and press Enter to search. Press Esc to cancel.