Cointime

Download App
iOS & Android

Massive Supply Chain Attack Targeting Small Number of Crypto Companies: Kaspersky

A supply chain attack installed a backdoor in computers around the world but has only been deployed in fewer than ten computers, cybersecurity company Kaspersky has reported. The deployments showed a particular interest in cyptocurrency companies, it added. 

Kaspersky said it suspected the involvement of the North Korea-linked threat actor Labyrinth Chollima. 3CX said of the infection:

“This appears to have been a targeted attack from an Advanced Persistent Threat, perhaps even state sponsored, that ran a complex supply chain attack and picked who would be downloading the next stages of their malware.”

The 3CX app is used by over 600,000 companies, including several major brands, Kapersky said, citing the maker. The infected app had DigiCert certification.

Comments

All Comments

Recommended for you

  • Lightning In A High Fee Environment: Implications for Bitcoin’s Scalability

    The topic of scaling Bitcoin dates back to its very first mailing post. In response to Satoshi’s original message, James McDonald said, “We very, very much need such a system, but the way I understand your proposal, it does not seem to scale to the required size” — a remark that probably wasn’t the welcome Satoshi had anticipated. Nonetheless, this marked the beginning of a seemingly never ending, complex debate.
  • Cointime May 3rd News Express

    1. The 133rd Ethereum ACDC meeting: The goal is to complete the devnet within 7-10 days
  • Cointime April 23th News Express

    1. EigenLayer: Deposit limits for all LST tokens will be removed on April 16
  • Cointime April 5th News Express

    1.Mystiko.Network Community Sale Completed, Total $11.25 Million in XZK Sold2.Solana Co-founder Responds to the Sharp Increase in Transaction Failure Rates: Patch Coming Soon3.Ethena USDe market value exceeds 2 billion US dollars, setting a new record4.Du Jun, Executive Director and CEO of Xinhuo & Founder of ABCDE: Xinhuo Technology and ABCDE will invest 100 million US dollars to support blockchain companies that promote social development 5.QCP Capital: Bitcoin is expected to return to $70,000 this week, while Ethereum continues to be weak6.bitSmiley Labs officially launches its independent ecosystem plan, bitUniverse, and reveals its OG pass bitDisc-Black Upgraded Priviledges 7.Avalanche Foundation launches ice-breaking plan, focusing on LST track in the first phase and funding 500,000 AVAX 8.SuperRare Expands into Bitcoin Ordinals with Killer Acid's Psychedelic Art Collection 9.A dormant whale address for 8 months deposited 1,100 BTC into Binance10.Meme exchange DerpDEX.com completes multi-million dollar strategic investment, with participation from ABO Digital and others
  • Terra founder Do Kwon to be extradited to U.S.

    Terra founder Do Kwon will be extradited to the United States.
  • Cointime February 3 News Express

    1. Ripple payment service "Ripple Payments" plans to return to the US market and launch targeted solutions
  • Cointime January 14 News Express

    1.Digital asset protocol Metaplex will list its Solana inscription on January 162.Investment bank TD Cowen: The U.S. SEC will not approve an Ethereum spot ETF in the short term3.Binance, Kraken and other nine trading platforms have been removed from Google App Store in India4.Barclays economists advance forecast for Fed rate cut to start from June to March5.The Chairman of the U.S. SEC issued a statement on the theft of the SEC's official Twitter account: The impact is still being evaluated and the company is cooperating with law enforcement agencies for
  • Cointime January 7th News Express

    1.Ordinals’ cumulative fee income exceeds 5,400 BTC
  • Cointime December 31st News Express

    1.Linea mainnet has crossed 305,685 ETH
  • WinRAR Zero-Day Vulnerability Allowed Hackers to Breach Crypto and Stock Trading Accounts

    Developers of the file compression software WinRAR have fixed a zero-day vulnerability that was being exploited by hackers to install malware on unsuspecting victims' computers. The vulnerability allowed hackers to breach online crypto and stock trading accounts. The exploit was used for approximately four months, during which time malicious RAR and ZIP archives were distributed on trading forums, infecting at least 130 devices.