Source: https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A6984897253320638464
CNET N. Korea’s Crypto Hackers Paving the Road to Nuclear Armageddon: One bad click: A single corrupted file can leave disaster in its wake. The Axie Infinity hack that netted North Korea over $600 million in crypto started with just that: a tainted PDF.
#ZeroTrust When #Every #Device & #Network is a #TrojanHorse: https://lnkd.in/eQc_gzw : SSRN: https://lnkd.in/ec99Zkd :
#AI #ML #DL #Quant #Cyber #Crypto #Quantum #Risk #Computing
Axie Infinity is a web browser #game similar to #Pokemon, except that the Axie creatures you battle are owned as #NFT’s and can be #traded for #crypto. To support this digital economy, developer Sky Mavis created its own #blockchain called #Ronin, whose sole purpose is to process #Axie Infinity transactions. At its peak in August 2021, the game was generating over $15 million a day. A senior #engineer who worked on Ronin was approached by #NorthKorea operatives on #LinkedIn earlier this year, according to a report from The Block. After several rounds of #interviews, the #engineer received a formal #joboffer via #PDF.
The Ronin blockchain runs on a #proof-of-#authority #model, wherein #validation #control is given to nine handpicked accounts. To gain control of the #blockchain, bad actors needed to control five of these nine validator accounts. When the senior engineer clicked the #infected #link, he unwittingly gave North Korean #hackers keys to four of those #validators. Once they were inside Axie Infinity’s #computer #system, hackers were able to get keys for a fifth. The $600 million was drained shortly after.
Sky Mavis employees are under constant advanced #spear-#phishing #attacks on various #social #channels and one employee was compromised. … The #attacker managed to leverage that access to #penetrate Sky Mavis #IT #infrastructure and gain access to the #validator #nodes.
It’s possible the North Korean operatives hired a #middleman company to orchestrate the #faux #employer #phishing #scheme. That’s what they did in 2019, paying an #actor to play an #executive in #fake #job #interviews with the goal of #infiltrating the #computer #systems of #Chile’s #Redbanc.*
It’s tempting to write off the Ronin hack as a disorganized #crypto company being exploited. But the same tactics have worked against world-renowned targets. In the infamous #Sony hack of 2014, hackers gained access to Sony’s computer network by pretending to be a businessman:
https://lnkd.in/eQc_gzw :
#FutureOfRisk: We Pioneered 30-Yrs Ago: It’s now #ISO #Standard:
* In the exponentially growing realms of the ‘invisible’ risks, those used to the pre-WWW era of ‘visible’ risks will be increasingly challenged to ‘see’ with their minds what they shall not be able to see with their eyes.:
https://lnkd.in/gcp_yHe :
Silicon Valley’s Next Big Thing™: CEO-CxO Know-Build-Monetize™ Networks: Join The CEO Metaverse™:
Global Risk Management Network, LLC: Future of AI-Computer Science-Data Science-Finance Are All Here