The Lazarus Group, a North Korean hacking organization, has deposited 400 Ethereum (ETH), valued at approximately $750,000, into Tornado Cash. This action is linked to a $1.4 billion hack of Bybit that occurred in February. In addition to the deposit, the group has been deploying a new malware known as 'BeaverTail,' which targets browsers and cryptocurrency wallets. Reports indicate that the Lazarus Group has also infiltrated the npm ecosystem by releasing six malicious packages aimed at stealing developers' credentials and deploying backdoors. Cybersecurity firm CyberArk has uncovered a separate cryptojacking campaign, named 'MassJacker,' which is targeting over 700,000 cryptocurrency wallets, altering clipboard data to redirect funds to attacker-controlled accounts. This campaign has reportedly led to $336,700 in stolen funds.
Malicious PyPI Packages Stole Cloud Tokens—Over 14,100 Downloads Before Removal https://t.co/E2hrS8ubOp
JUST IN: MASSIVE CRYPTOJACKING CAMPAIGN TARGETING 700K WALLETS UNCOVERED BY CYBERSECURITY FIRM CYBERARK. Source: Cryptonews https://t.co/apyTmL5Eqo
🚨 A new cryptojacking campaign has been uncovered by cybersecurity firm Ciberark, involving over 700K cryptocurrency addresses! 💻💰 Dubbed "Massjacker," this malware hijacks the clipboard of infected devices, altering crypto addresses and redirecting deposits to unintended…