Seoul: North Korean hacking group Lazarus is suspected to be behind a recent breach of around 45 billion won (US$30.6 million) worth of cryptocurrency from South Korea's largest crypto exchange Upbit, sources said Friday.
According to Yonhap News Agency, government and business sources indicated that authorities plan to carry out an on-site investigation at the crypto exchange, operating under the belief that Lazarus orchestrated the hacking. Dunamu, which manages Upbit, confirmed on Thursday the unauthorized transfer of 44.5 billion won worth of Solana-affiliated assets to an unauthorized wallet address and assured stakeholders of its intention to cover the full amount using assets the company possesses.
The hacking group Lazarus had previously been implicated in the theft of 58 billion won worth of Ethereum from Upbit in 2019. Authorities noted that the methods used in this recent incident closely resembled those employed in the 2019 theft. Officials suggested that instead of directly attacking the server, the hackers might have compromised administrators' accounts or impersonated administrators to execute the transfer.
Experts highlighted that this hacking incident occurred as Pyongyang seeks to raise funds amid a foreign currency shortage. A security official explained that it is typical for Lazarus to transfer cryptocurrencies to wallets at other exchanges and attempt money laundering, a strategy that complicates transaction tracking.
Additionally, it was suggested that the hackers might have deliberately targeted the attack on Thursday, coinciding with Naver Corp.'s announcement of its decision to acquire Dunamu as a wholly owned subsidiary of Naver Financial through a share-swap deal. Another security official noted that hackers often have a strong inclination towards self-display, which could have influenced the timing of the attack.