North Korean hackers deploy ‘Durian’ malware, targeting crypto firms
North Korean hackers are utilizing a “striking” new malware variant dubbed “Durian” to reportedly launch attacks on South Korean crypto firms.
The North Korean hacking group Kimsuky used the new malware in a series of targeted attacks on at least two cryptocurrency firms so far, according to a May 9 threat report from cybersecurity firm Kaspersky.
This was done through a “persistent” attack by exploiting legitimate security software used exclusively by crypto firms in South Korea.
The previously unknown Durian malware acts as an installer that deploys a continued stream of malware including a backdoor known as “AppleSeed,” a custom proxy tool known as LazyLoad, and other legitimate tools such as Chrome Remote Desktop.
“Durian boasts comprehensive backdoor functionality, enabling the execution of delivered commands, additional file downloads, and exfiltration of files,” wrote Kaspersky.
Additionally, Kaspersky noted that LazyLoad was also used by Andariel, a sub-group within fellow North Korean hacking consortium Lazarus Group — something that suggested a “tenuous” connection between Kimsuky and the more notorious hacking group.
Related: North Korean Lazarus hacker group using LinkedIn to target and steal assets: Report
First emerging in 2009, Lazarus has established itself as one of the most notorious groups of crypto hackers.
On April 29, independent blockchain sleuth ZachXBT revealed that the Lazarus group had successfully laundered over $200 million in ill-gotten crypto between 2020 and 2023.
In total, the Lazarus Group is accused of stealing over $3 billion in crypto assets in the six years leading up to 2023.
Lazarus was credited with stealing over 17% — a little over $309 million — of the total stolen funds in 2023. Throughout 2023 more than $1.8 billion worth of crypto was lost to hacks and exploits, according to a Dec. 28 report by Immunefi.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Whale Sells $5.48M in TRUMP Token, Gains $483K
A crypto whale offloaded 630,339 TRUMP tokens for $5.48M, pocketing nearly $483K in profit at $8.70 per token.Whale Exits TRUMP Token with Nearly Half a Million in ProfitSmart Profit-Taking or Early Exit?Whale Moves as a Market Signal

Buy Low, Fly High: Arctic Pablo at $0.000099 Eyes $0.008 Surge, While Fwog And Pudgy Penguins Push Boundaries
Explore Arctic Pablo Coin's presale, Pudgy Penguins' gaming expansion, and Fwog's market trends. Discover the Top New Meme Coins to Invest in April 2025.Arctic Pablo Coin (APC): Staking and RewardsArctic Pablo Coin (APC): Presale Reaches Frostbite CityPudgy Penguins: Expanding into Mobile GamingFwog: Gaining Momentum in the Meme Coin MarketWrapping Up: Arctic Pablo Coin (APC) Stands OutFor More Information:

Australian Court Overturns License Ruling Against Block Earner, Sides with Fintech in Landmark Crypto Case
In a significant legal win for Australia’s crypto and fintech industry, the Federal Court has overturned a previous ruling that required digital finance firm Block Earner to obtain a financial services license for its discontinued fixed-yield crypto product.

Symbiotic Raises $29 Million to Build Universal Staking Coordination Layer
Symbiotic, a decentralised finance (DeFi) protocol, has secured $29 million in a funding round led by Paradigm and cyber.Fund.

Trending news
MoreCrypto prices
More








