Microsoft Warns Cryptocurrency Firms Against Complex Cyber-Attacks
, 2022-12-07 12:00:00,
Threat actors have been observed targeting companies operating within the cryptocurrency industry for financial gain.
According to a new advisory published by Microsoft on Tuesday, attacks targeting this market have taken several forms over the past few months, including fraud, vulnerability exploitation, fake applications and info stealer deployment.
“We are also seeing more complex attacks wherein the threat actor shows great knowledge and preparation, taking steps to gain their target’s trust before deploying payloads,” the tech giant wrote.
One of the threat actors observed by Microsoft and operating in this industry is DEV-0139, who used Telegram groups to facilitate communication between VIP clients and cryptocurrency exchange firms and thus identified their target among the members.
“The threat actor posed as representatives of another cryptocurrency investment company, and in October 2022, invited the target to a different chat group and pretended to ask for feedback on the fee structure used by cryptocurrency exchange platforms,” Microsoft explained.
“The threat actor had a broader knowledge of this specific part of the industry, indicating that they were well prepared and aware of the current challenge the targeted companies may have.”
After establishing the first contact with potential victims, DEV-0139 sent a weaponized Excel file that contained tables about fee structures among cryptocurrency exchange companies.
Microsoft suggested the…
,
To read the original article from news.google.com Click here