Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»North Korean Group TA444 Shows ‘Startup’ Culture, Tries Numerous Infection Methods
North Korean Group TA444 Shows 'Startup' Culture, Tries Numerous Infection Methods
Security

North Korean Group TA444 Shows ‘Startup’ Culture, Tries Numerous Infection Methods

October 11, 2023No Comments2 Mins Read

A previously unknown, financially motivated North Korea state-sponsored threat actor has been observed testing several infection methods in the wild while adhering to a ‘startup’ culture mentality.

The findings come from security researchers at Proofpoint, who called the group TA444 and said it has been active in its current form of targeting cryptocurrency exchanges since at least 2017.

According to an advisory published earlier today, the group then adopted an upstart mentality at the end of 2022.

“Equally as surprising as the variance in delivery methods is the lack of a consistent payload at the end of the delivery chains,” reads the advisory from senior threat researcher Greg Lesnewich and the Proofpoint threat research team.

“When other financially-oriented threat actors test delivery methods, they tend to load their traditional payloads; this is not the case with TA444. This suggests […] an embedded, or at least a devoted, malware development element alongside TA444 operators.”

Further, Proofpoint said they noticed a complete marketing strategy designed by TA444 to increase its annual recurring revenue (ARR) potential.

“It all starts with crafting lure content that may be of interest or necessity to the target. These can include analyses of cryptocurrency blockchains, job opportunities at prestigious firms, or salary adjustments.”

In terms of tools used during the attacks, Lesnewich wrote TA444 used “an impressive set of post-exploitation backdoors in its history.”

The list includes msoRAT, Cardinal, the Rantankba suite, Cheesetray and Dyepack, alongside passive backdoors, virtualized listeners and browser extensions to facilitate theft.

“While we may poke fun at its broad campaigns and ease of clustering, TA444 is an astute and capable adversary that is willing and able to defraud victims for hundreds of millions of dollars,” Proofpoint wrote.

See also  French Probe After €3M Ransom Case

“TA444 and related clusters are assessed to have stolen nearly $400m […] worth of cryptocurrency and related assets in 2021. In 2022, the group surpassed that value in a single heist worth over $500m, gathering more than $1bn during 2022.”

The Proofpoint report comes days after the US Federal Bureau of Investigation (FBI) confirmed that North Korea’s Lazarus Group was behind the $100m theft from cryptocurrency firm Harmony.

Source link

Culture Group Infection Korean Methods North Numerous Shows Startup TA444

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

TRUMP Coin Insider Dumped $65M in Pump.fun’s PUMP Token

February 19, 2026

Elixir Protocol secures $7.5 million Series A funding at $100 million valuation

October 19, 2023

WIF Price Prediction: Critical $0.20 Decision Point Could Trigger 15% Move in 72 Hours

April 22, 2026

Type above and press Enter to search. Press Esc to cancel.