|

South Korean users of crypto exchange UpBit fell victim to a phishing attack

  • Hackers sent emails with malicious code to UpBit users.
  • The same methods were used in the course of the January attack on the South Korean government agencies.

The South Korean cryptocurrency exchange might have fallen victim to hackers from neighboring North Korea. The attackers allegedly exploited smart phishing techniques, according to the report published by the security company East Security.

On May 28, the hacker or a group of hackers sent a malicious email to UpBit customers requesting additional information about customer’s fictional sweepstakes payout. However, the company never sent such email and it did not come from any of the servers belonging the exchange.

The mail contained an attachment with the documentation for the payout. Once a user opened the fine, it would run a malicious code embedded therein and sent information about the user’s machine along with their private keys and credentials to hackers. Moreover, the virus also connected the infected computer to a command and control system to allow hackers accessing it remotely.

“In analyzing attack tools and malicious codes used by hacker groups, there are unique characteristics we saw. As bitcoin prices rise, more and more customers are using exchanges. This means that the number of victims has increased, which means that the possibility of stealing passwords stored in the exchange has increased,” the head of the ESRC Center at East Security Mun Jong-hyun commented.

He also noted that similar attacks known as Operation Fake Striker were made on Korean government agencies in January. 

The hackers password-protected the file with the malicious code, which made it harder for traditional anti-virus tools to detect a threat. The experts urge users to be vigilant and never open or install suspicious files.

“We have not heard of any reported damage. In order to avoid cyber attacks, you should not install or click suspicious files or documents,” noted Mun Jong-hyun.

Author

Tanya Abrosimova

Tanya Abrosimova

Independent Analyst

 

More from Tanya Abrosimova
Share:

Editor's Picks

Hyperliquid Price Forecast: HYPE rises on commodities demand amid US-Iran war

Hyperliquid (HYPE) steadies above $33 at press time on Tuesday, marking its fourth consecutive day of recovery in a broadly volatile market due to the ongoing US-Israel strikes on Iran.

Stellar Price Forecast: XLM risks deeper losses as derivatives metrics turn negative

Stellar is trading red below $0.16 at the time of writing, after a slight recovery the previous day. Weakening derivatives data caps the recovery, while an unfavorable technical outlook projects a deeper correction for the XLM token in the upcoming days.

Aave Price Forecast: AAVE tests channel resistance as ParaFi Capital deposit, bearish derivatives data caps upside

Aave (AAVE) trades around $120 on Tuesday, testing the channel resistance, signaling that sellers remain active in the zone. Lookonchain data shows that ParaFi Capital transferred 42,000 AAVE tokens to Coinbase Prime over the past 10 hours, often interpreted as a potential selling signal.

CME Group's futures suite now covers over 75% of total crypto market cap

CME Group announced that its crypto futures offering now covers over 75% of the total digital asset market cap, following the launch of its Cardano (ADA), Chainlink (LINK) and Stellar (XLM) products.

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: Another month of losses, and it’s been five

Bitcoin (BTC) price is stabilizing around $68,000 at the time of writing on Friday, but the Crypto King is poised to close February on a fragile footing, marking its fifth consecutive month of losses since October and a rare start to the year with back-to-back monthly corrections.