$600 BONUS USING OUR REFERRAL CODE $600 BONUS USING OUR REFERRAL CODE $600 BONUS USING OUR REFERRAL CODE
Română | English | Español | Français
Market Cap: $ 3.27 T | 24h Vol.: $ 96.64 B | Dominance: 65.00%
crypto.ro
bitcoinBTC/USD
$ 107,502.00 0.01%
ethereumETH/USD
$ 2,427.98 0.85%
  • NEWS
    • Bitcoin
    • Ethereum
    • Solana
    • XRP
    • Cardano
    • Dogecoin
    • Binance
  • LEARN
    • Guides
    • Binance Referral Code
    • Best Crypto Exchanges
    • Best Crypto to Buy
    • Best Bitcoin Casinos
    • Reviews
    • PrimeXBT
    • Bybit
    • Bitget
    • YouHodler
    • Resources
    • About Bitcoin
    • Dictionary
    • ACADEMYCRYPTO COURSE
    • Bitcoin
    • Dictionary
  • MARKET
    • Prices
    • Bitcoin
    • Ethereum
    • BNB
    • Solana
    • Exchanges
    • Binance
    • Bybit
    • Bitget
    • PrimeXBT
    • Tools
    • Converter
    • Top Gainers Today
    • CryptocurrenciesLIVE
    • ExchangesTRADE
    • Converter
    • Top gainers today
GET $600 WELCOME BONUS
No Result
View All Result
crypto.ro
  • NEWS
    • Bitcoin
    • Ethereum
    • Solana
    • XRP
    • Cardano
    • Dogecoin
    • Binance
  • LEARN
    • Guides
    • Binance Referral Code
    • Best Crypto Exchanges
    • Best Crypto to Buy
    • Best Bitcoin Casinos
    • Reviews
    • PrimeXBT
    • Bybit
    • Bitget
    • YouHodler
    • Resources
    • About Bitcoin
    • Dictionary
    • ACADEMYCRYPTO COURSE
    • Bitcoin
    • Dictionary
  • MARKET
    • Prices
    • Bitcoin
    • Ethereum
    • BNB
    • Solana
    • Exchanges
    • Binance
    • Bybit
    • Bitget
    • PrimeXBT
    • Tools
    • Converter
    • Top Gainers Today
    • CryptocurrenciesLIVE
    • ExchangesTRADE
    • Converter
    • Top gainers today
crypto.ro
Home News

North Korean hackers employ roughly 500 phishing domains to steal NFTs

The hackers constructed fake websites that looked like DeFi platforms, NFT initiatives, and even NFT marketplaces. 

Floshady FloshadyVerified Author
Dec 27, 2022
3 min. read
Share on TwitterShare on TelegramSend on WhatsappShare on Facebook

Approximately 500 phishing domains are apparently being used by hackers affiliated with North Korea’s Lazarus Group to deceive victims in a large phishing effort targeting investors in non fungible tokens (NFT). 

North Korean Advanced Persistent Threat (APT) groups

On December 24, the blockchain security company SlowMist published a report outlining the strategies employed by North Korean Advanced Persistent Threat (APT) groups to separate NFT investors from their NFTs. These strategies included the use of dummy websites impersonating various NFT-related platforms and projects.

These bogus websites, which imitate well-known NFT marketplaces like OpenSea, X2Y2, and Rarible, include one that pretends to be a World Cup project and others that counterfeit other well-known NFT projects.

One technique involved creating fake NFT-related websites with malicious Mints to steal NFTs. They used nearly 500 different domain names and sold them on platforms such as @OpenSea, @X2Y2, and @rarible.

One of the earliest incidents can be traced back to 7 months ago. pic.twitter.com/4COsMuR80x

— SlowMist (@SlowMist_Team) December 24, 2022

One of the strategies is to have these fake websites provide “malicious mints,” which trick the users into believing they are minting real NFTs by linking their wallets to the website.

But since the NFT is basically a scam, the victim’s wallet is now open to the hackers who have now gained access to it.

In addition, the analysis showed that many of the phishing websites shared the same Internet Protocol (IP), with 372 NFT phishing websites sharing a single IP and another 320 NFT phishing websites using a different IP. 

North Korean hackers employ roughly 500 phishing domains to steal NFTs
An example phishing website Source: SlowMist

One of the earliest registered domain names was roughly seven months ago, according to SlowMist, who said that the phishing campaign has been going on for a while.

Hackers collected visitor’s data on external websites

The use of visitor data collection and data storage on external websites, the use of an HTTP request path for the NFT item price list, and the connecting of photos to target projects were additional unique phishing techniques employed by the group.

Analyzing the code of behavior, SlowMist discovered that once the hacker has the visitor’s data, they will now utilize a variety of attack scripts to target the victim, giving them access to their plug-in wallets, approvals, and records, as well as sensitive information like the victim’s approve record and sigData.

With access to the victim’s wallet made possible by all this information, the hacker can then see all of their digital assets. 

SlowMist’s research on the phishing scam

As the research only examined a small percentage of the materials and just some of the phishing traits of the North Korean hackers were recovered, SlowMist stressed that this is only the “tip of the iceberg” as it took to Twitter to share a thread discussing the issue.

https://twitter.com/SlowMist_Team/status/1606651673023242241

SlowMist in his thread said that there were multiple attack vectors, but their focus would be on NFT phishing for confidentiality and security reasons. It made reference to a tweet posted by a Twitter user with the account name PhantomXsec on the 4th of September, which pointed at the North Korean APT group as being responsible for crypto phishing and campaigns spanning over 190 domains.

For instance, one phishing account was able to benefit 1,055 NFTs and earn almost 300 Ether by selling it, totaling $367,000 through its phishing techniques. It also stated that the Naver phishing operation, which was originally reported by Prevailion on March 15, was carried out by the same North Korean APT organization.

In 2022, North Korea served as the focal point for a number of cryptocurrency theft activities. The National Intelligence Service (NIS) of South Korea reported on December 22 that North Korea had stolen cryptocurrencies worth $620 million just this year.

Japan’s National Police Agency issued a warning to the nation’s crypto-asset enterprises in October, recommending that they exercise caution in the face of the North Korean hacking organization. SlowMist advocates enhancing security awareness and the capacity to spot such dangers if one wants to avoid falling victim to phishing attempts.

Tags: NFTNorth koreaphishing

Related articles

What is Blum Coin?

What is Blum Coin?

Jun 27, 2025
Bitcoin's $2.138T Market Cap Flips Google, Becomes 6th World Asset

Bitcoin’s $2.138T Market Cap Flips Google, Becomes 6th World Asset

Jun 27, 2025
Kraken Launches 2P2 Payments App, Krak, in Over 160 Countries

Kraken Launches 2P2 Payments App, Krak, in Over 160 Countries

Jun 26, 2025
$15B Bitcoin Options and $2.3B Ethereum Options Expire on June 27

$15B Bitcoin Options and $2.3B Ethereum Options Expire on June 27

Jun 26, 2025
Please login to join discussion
Binance Binance Binance
COMMUNITY
Facebook Instagram Youtube Tiktok Telegram Pinterest Linkedin

NEWS

  • Crypto
  • Bitcoin
  • Ethereum
  • Solana

MARKET

  • Crypto Prices
  • Exchanges
  • Top gainers today
  • Price predictions

LEARN

  • Dictionary
  • Best Exchanges
  • Crypto to Buy

REVIEWS

  • Bybit
  • Bitget
  • Youhodler
  • PrimeXBT

OPPORTUNITIES

  • NUMERIS Club
  • Careers
  • Binance Bonus

COMPANY

  • About us
  • Media Kit
  • Advertise
  • Contact

© 2020 – 2025 crypto.ro® – All rights reserved.

  • Terms & conditions
  • Cookie policy
  • Privacy policy

Disclaimer: By using this website, you agree to the Terms and Conditions. crypto.ro has no affiliation or relationship with any coin, business, project, or event, unless otherwise specified. None of the information you’ve read on crypto.ro should be taken as investment advice. Buying and trading cryptocurrencies should be considered a high-risk activity. Please do your own due diligence before making any investment decision. crypto.ro is not responsible, directly or indirectly, for any damage or loss incurred, alleged or otherwise, in connection with the use or reliance on any content you have read on the site.

No Result
View All Result
  • News
    • Crypto
    • Bitcoin
    • Ethereum
    • NFT
  • Analysis
  • Education
    • Crypto academy
    • Dictionary
    • Bitcoin
  • Market
    • Cryptocurrencies
    • Exchanges
    • Converter
    • Top gainers today
  • Company
    • About us
    • Ambassadors
    • Affiliate program
    • Events
    • Advertise
    • Contact
Română | English | Español | Français
crypto.ro logo

© 2020 - 2025 crypto.ro®

We use cookies to offer you a better browsing experience.Continuing to use our site consents to use of cookies.Cookie Policy
Hours
Minutes
Seconds