{"id":22745,"date":"2025-04-05T07:00:00","date_gmt":"2025-04-05T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/seed-phrase-poison-a-contagious-coinbase-job-ruse-and-other-cybersecurity-news\/"},"modified":"2025-04-05T07:00:00","modified_gmt":"2025-04-05T04:00:00","slug":"seed-phrase-poison-a-contagious-coinbase-job-ruse-and-other-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/seed-phrase-poison-a-contagious-coinbase-job-ruse-and-other-cybersecurity-news\/","title":{"rendered":"Seed-phrase poison, a contagious \u2018Coinbase job\u2019 ruse, and other cybersecurity news"},"content":{"rendered":"<p>We collected the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Coinbase and Ledger customers targeted by seed\u2011phrase phishing.<\/li>\n<li>North Korean hackers posed as HR managers of major crypto exchanges.<\/li>\n<li>Members of the group that breached NATO\u2019s portal suggested their leader had been arrested.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Coinbase and Ledger customers targeted by seed-phrase phishing campaign<\/strong><\/h2>\n<p>Researchers at SilentPush <a href=\"https:\/\/www.silentpush.com\/blog\/poisonseed\/\">uncovered<\/a> the PoisonSeed phishing campaign, which sends emails containing seed phrases to steal cryptocurrency.<\/p>\n<p>First, attackers spin up spoofed pages of well-known mass-mailing platforms, including Mailchimp, SendGrid, HubSpot, Mailgun and Zoho. They use them to compromise corporate email accounts of various marketers and then send spam from those inboxes. The hackers focus on Coinbase customers and Ledger hardware\u2011wallet owners.<\/p>\n<p>The messages typically mimic an urgent alert such as \u201cCoinbase is moving to self-custody wallets\u201d and include a seed phrase. Recipients are told to enter it when creating a new wallet to \u201csafely transfer assets\u201d as part of an update or migration.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"651\" height=\"1024\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-671-651x1024.png\" alt=\"image-671\" class=\"wp-image-255830\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-671-651x1024.png 651w, https:\/\/u1f987.com\/wp-content\/uploads\/image-671-191x300.png 191w, https:\/\/u1f987.com\/wp-content\/uploads\/image-671-768x1207.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/image-671-977x1536.png 977w, https:\/\/u1f987.com\/wp-content\/uploads\/image-671-1303x2048.png 1303w, https:\/\/u1f987.com\/wp-content\/uploads\/image-671.png 1600w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><figcaption class=\"wp-element-caption\">Fake email purporting to be from Coinbase. Data: SilentPush.<\/figcaption><\/figure>\n<p>If the target complies, the attacker gains full control of their funds.<\/p>\n<h2 class=\"wp-block-heading\"><strong>North Korean hackers posed as HR managers from major crypto exchanges<\/strong><\/h2>\n<p>Experts at Sekoia flagged a new <a href=\"https:\/\/blog.sekoia.io\/clickfake-interview-campaign-by-lazarus\/\">ClickFix tactic<\/a> adopted by the North Korean hacking group Lazarus Group to target jobseekers in AI and crypto.<\/p>\n<p>Candidates receive invitations from fake interview sites. When they click through and view content, they encounter errors. The page offers to \u201cfix\u201d the issue by running PowerShell commands that fetch malware.<\/p>\n<p>In this campaign the hackers impersonate well-known crypto projects, including Coinbase, KuCoin, Kraken, Circle, Securitize, BlockFi, Tether, Robinhood and Bybit.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"809\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-673-1024x809.png\" alt=\"image-673\" class=\"wp-image-255832\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-673-1024x809.png 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/image-673-300x237.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/image-673-768x607.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/image-673.png 1164w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Brands used by the hackers. Data: Sekoia.<\/figcaption><\/figure>\n<p>Beyond stealing crypto, the malware can perform file operations and shell commands, exfiltrate cookies, browsing history and saved passwords, and collect system metadata.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Members of the group that breached NATO\u2019s portal suggest their leader was arrested<\/strong><\/h2>\n<p>One member of the SiegedSec hacking group, responsible for breaching NATO\u2019s portal, the Heritage Foundation think-tank and a nuclear laboratory in Idaho, suggested that the FBI searched the home of their leader, known as vio, and arrested her. This was reported by <a href=\"https:\/\/www.dailydot.com\/debug\/furry-hackers-fbi-raided\/\">Daily Dot<\/a>, citing a March 26 tweet.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">I regret to inform you that vio&#8217;s location was raided earlier today. She is no longer accessible, contactable, or reliable.<\/p>\n<p>I&#8217;m available to address any inquiries you may have.<\/p>\n<p>\u2014 . (@mewmrrpmeow) <a href=\"https:\/\/twitter.com\/mewmrrpmeow\/status\/1905042931137773694?ref_src=twsrc%5Etfw\">March 26, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cI regret to inform you that vio\u2019s location was raided this morning. She is no longer available, cannot be reached, and [her contact from this moment] is unreliable,\u201d wrote the user under the handle mewmrrpmeow.<\/p>\n<\/blockquote>\n<p>A day later, a new <a href=\"https:\/\/x.com\/mewmrrpmeow\/status\/1905130117602459702\">post<\/a> noted that \u201cthe silence around the SiegedSec case is concerning\u201d.<\/p>\n<p>Details remain scarce. SiegedSec disbanded in July 2024 after leaders at the Heritage Foundation warned that information about the hackers had been passed to the FBI. The bureau has not publicly announced an investigation or any charges.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Europol shuts KidFlix platform with child abuse content<\/strong><\/h2>\n<p>German law-enforcement, together with Dutch counterparts, <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/global-crackdown-kidflix-major-child-sexual-exploitation-platform-almost-two-million-users\">took down<\/a> one of the largest dark\u2011web platforms distributing <span data-descr=\"child sexual abuse\" class=\"old_tooltip\">CSAM<\/span> materials, Kidflix. The operation began in 2022 and concluded on March 11, 2025, but details have only now been disclosed.<\/p>\n<p>Over its course, 79 individuals were arrested, the identities of 1,393 suspects established, and more than 3,000 electronic devices seized. The site\u2019s server was also confiscated.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"597\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-670-1024x597.png\" alt=\"image-670\" class=\"wp-image-255829\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/image-670-1024x597.png 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/image-670-300x175.png 300w, https:\/\/u1f987.com\/wp-content\/uploads\/image-670-768x448.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/image-670-1536x896.png 1536w, https:\/\/u1f987.com\/wp-content\/uploads\/image-670.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Data: Europol.<\/figcaption><\/figure>\n<p>Since its launch in 2021, Kidflix hosted more than 91,000 unique videos with a total length of 6,288 hours. Users exceeded 1.8 million. They paid for content in cryptocurrencies and could earn internal tokens for activity.<\/p>\n<p>Case materials have been forwarded to investigative authorities in 35 countries for follow-up with suspects.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Paradigm dissects cases involving North Korea\u2019s leading crypto hackers<\/strong><\/h2>\n<p>Paradigm published a detailed <a href=\"https:\/\/www.paradigm.xyz\/2025\/03\/demystifying-the-north-korean-threat\">report<\/a> on North Korean cybercriminal groups behind attacks on organisations and individuals worldwide.<\/p>\n<p>Beyond the best-known Lazarus Group, the researchers describe Contagious Interview and Wagemole, which run a scheme hiring IT staff. The hackers steal a wide range of data, including cryptocurrencies.<\/p>\n<p>AppleJeus distributes malware disguised as trading apps and crypto utilities, while Dangerous Password uses social engineering to target holders of digital assets.<\/p>\n<p>The most sophisticated, the analysts say, is TraderTraitor, which picks victims among bitcoin exchanges and major industry firms, compromising them via highly engineered spear\u2011phishing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>US TikTok ban delayed<\/strong><\/h2>\n<p>On April 4, US President Donald Trump <a href=\"https:\/\/truthsocial.com\/@realDonaldTrump\/posts\/114280893859636366\">extended<\/a> by 75 days the deadline for TikTok owner ByteDance to sell its US assets to avoid a block. The head of state expressed hope for continued \u201cgood\u2011faith cooperation with China\u201d.<\/p>\n<p><iframe src=\"https:\/\/truthsocial.com\/@realDonaldTrump\/114280893859636366\/embed\" class=\"truthsocial-embed\" style=\"max-width: 100%; border: 0\" width=\"600\" allowfullscreen=\"allowfullscreen\"><\/iframe><script src=\"https:\/\/truthsocial.com\/embed.js\" async=\"async\"><\/script><\/p>\n<p><a href=\"https:\/\/www.reuters.com\/markets\/deals\/trump-tiktok-sale-deadline-looms-us-looks-deal-2025-04-04\/\">Reuters<\/a>, citing sources, reported that the Chinese side paused the deal after 54% <a href=\"https:\/\/u1f987.com\/en\/news\/trump-declares-liberation-day-with-new-tariffs\">tariffs<\/a> were imposed on imports of its goods into the US.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>OKX will pay Malta\u2019s regulator a <a href=\"https:\/\/u1f987.com\/en\/news\/okx-fined-1-2-million-by-maltese-regulator\">fine<\/a> of $1.2m.<\/li>\n<li>A US court <a href=\"https:\/\/u1f987.com\/en\/news\/us-court-fines-cls-global-428059-for-wash-trading\">fined<\/a> CLS Global $428,059 for sham trading.<\/li>\n<li>Since the start of 2024, the crypto industry has <a href=\"https:\/\/u1f987.com\/en\/news\/cryptocurrency-industry-faces-3-83-billion-loss-from-hacks-since-2024\">lost<\/a> $3.83bn to hacks.<\/li>\n<li>UPCX <a href=\"https:\/\/u1f987.com\/en\/news\/upcx-halts-operations-following-unauthorized-70-million-withdrawal\">halted operations<\/a> after an unauthorized $70m outflow.<\/li>\n<li>The zkLend hacker reported the <a href=\"https:\/\/u1f987.com\/en\/news\/hacker-claims-loss-of-2930-eth-on-phishing-site-after-zklend-breach\">loss of 2,930 ETH<\/a> on a phishing site.<\/li>\n<li>0xbow implemented Vitalik Buterin\u2019s idea for an <a href=\"https:\/\/u1f987.com\/en\/news\/0xbow-implements-vitalik-buterins-alternative-to-tornado-cash\">alternative to Tornado Cash<\/a>.<\/li>\n<li>Smartphones that steal cryptocurrency <a href=\"https:\/\/u1f987.com\/en\/news\/counterfeit-smartphones-with-cryptocurrency-stealing-malware-emerge-in-unofficial-stores\">appeared in<\/a> unofficial stores.<\/li>\n<li>Chainalysis <a href=\"https:\/\/u1f987.com\/en\/news\/darknet-markets-revert-to-bitcoin-following-monero-delisting-says-chainalysis\">reported<\/a> dark\u2011web platforms returning to bitcoin.<\/li>\n<li>Iranian security forces stole cryptocurrency <a href=\"https:\/\/u1f987.com\/en\/news\/iranian-officials-accused-of-embezzling-21-million-in-cryptocurrency\">worth $21m<\/a>.<\/li>\n<li>A \u201csly attack\u201d on the SIR.trading protocol led to <a href=\"https:\/\/u1f987.com\/en\/news\/cunning-attack-on-sir-trading-protocol-wipes-out-tvl\">TVL being wiped out<\/a>.<\/li>\n<li>Analysts revealed <a href=\"https:\/\/u1f987.com\/en\/news\/experts-unveil-details-of-oracle-manipulation-attack-on-venus-protocol\">details of the attack<\/a> on Venus Protocol involving oracle manipulation.<\/li>\n<li>Experts <a href=\"https:\/\/u1f987.com\/en\/news\/experts-uncover-android-trojan-targeting-crypto-wallets\">found<\/a> an Android trojan targeting crypto wallets.<\/li>\n<li>The creator of LIBRA and MELANIA <a href=\"https:\/\/u1f987.com\/en\/news\/libra-and-melania-creator-begins-asset-sell-off\">began selling off<\/a> assets.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to read this weekend?<\/strong><\/h2>\n<p>In ForkLog\u2019s monthly digest, we discuss the fallout from the Bybit breach with Irakli Dizenko, an expert in deploying HAPI crypto\u2011security tools.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We collected the week\u2019s most important cybersecurity news. Coinbase and Ledger customers targeted by seed\u2011phrase phishing. North Korean hackers posed as HR managers of major crypto exchanges. Members of the group that breached NATO\u2019s portal suggested their leader had been arrested. Coinbase and Ledger customers targeted by seed-phrase phishing campaign Researchers at SilentPush uncovered the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":22744,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-22745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"80","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/22745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=22745"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/22745\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/22744"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=22745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=22745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=22745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}