|

South Korean users of crypto exchange UpBit fell victim to a phishing attack

  • Hackers sent emails with malicious code to UpBit users.
  • The same methods were used in the course of the January attack on the South Korean government agencies.

The South Korean cryptocurrency exchange might have fallen victim to hackers from neighboring North Korea. The attackers allegedly exploited smart phishing techniques, according to the report published by the security company East Security.

On May 28, the hacker or a group of hackers sent a malicious email to UpBit customers requesting additional information about customer’s fictional sweepstakes payout. However, the company never sent such email and it did not come from any of the servers belonging the exchange.

The mail contained an attachment with the documentation for the payout. Once a user opened the fine, it would run a malicious code embedded therein and sent information about the user’s machine along with their private keys and credentials to hackers. Moreover, the virus also connected the infected computer to a command and control system to allow hackers accessing it remotely.

“In analyzing attack tools and malicious codes used by hacker groups, there are unique characteristics we saw. As bitcoin prices rise, more and more customers are using exchanges. This means that the number of victims has increased, which means that the possibility of stealing passwords stored in the exchange has increased,” the head of the ESRC Center at East Security Mun Jong-hyun commented.

He also noted that similar attacks known as Operation Fake Striker were made on Korean government agencies in January. 

The hackers password-protected the file with the malicious code, which made it harder for traditional anti-virus tools to detect a threat. The experts urge users to be vigilant and never open or install suspicious files.

“We have not heard of any reported damage. In order to avoid cyber attacks, you should not install or click suspicious files or documents,” noted Mun Jong-hyun.

Author

Tanya Abrosimova

Tanya Abrosimova

Independent Analyst

 

More from Tanya Abrosimova
Share:

Editor's Picks

Ripple tests recovery strength amid steady ETF inflows, growing retail interest

Ripple (XRP) continues to demonstrate notable resilience as the cryptocurrency market navigates the persistent war in the Middle East after the United States (US) and Israel attacked Iran on Saturday.

Bitcoin extends gains as ETF inflows persist despite broadening US-Iran war

Bitcoin hovers around $73,000 on Thursday, driven by the US Stock market recovery, boosting risk-on sentiment. Data shows analysts are mostly bullish on Bitcoin, citing renewed demand from institutional investors, on-chain holders, and the derivatives market.

Crypto Today: Bitcoin, Ethereum, XRP hold weekly gains despite US-Iran war

The cryptocurrency market is gaining strength on Thursday, building on Wednesday's upswing, which saw Bitcoin reach a weekly high above $74,000. Ethereum and Ripple are moderating their recent gains amid uncertainty stemming from the escalating war in the Middle East.

Pi Network eyes breakout rally as broader market recovers

Pi Network (PI) price extends gains above $0.1900 at press time on Thursday, following a 7% increase the previous day. The upcoming token unlock of more than 20 million PI tokens on Saturday looms over the short-term recovery. 

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: Another month of losses, and it’s been five

Bitcoin (BTC) price is stabilizing around $68,000 at the time of writing on Friday, but the Crypto King is poised to close February on a fragile footing, marking its fifth consecutive month of losses since October and a rare start to the year with back-to-back monthly corrections.