Also known as: MASAN, CryptoCore, MIDNIGHT NEPTUNE, tracked as, BlueNoroff, other names, such as Lockbit 2.0, Ryuk, APT38
CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing techniques that lead to LONEJOGGER malware infections. The group has leveraged social engineering tactics, including deepfake technology and hijacked YouTube accounts, to execute sophisticated giveaway scams that deceive victims into sending cryptocurrencies. Their operations have involved the misuse of platforms like Gemini for reconnaissance and the development of fraudulent content. Additionally, CryptoCore has been linked to a variety of campaigns, including Dangerous Password and SnatchCrypto, focusing on financial gain through cryptocurrency theft.
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
41
Tools
0
Campaigns
56
IOCs
0
Observed Data
3
Tactics