Bitrefill blames North Korean Lazarus group for cyberattack

Bitrefill blames North Korean Lazarus group for cyberattack

Bitrefill says a March breach was likely carried out by North Korea-linked Bluenoroff (Lazarus/APT38), with investigators citing similar tactics, malware, reused IPs/emails, and on-chain tracing as indicators. Attackers used a compromised employee laptop and stolen legacy credentials to access production secrets, drain some hot wallets, and expose about 18,500 purchase records (including 1,000 names), while Bitrefill reports minimal losses and is strengthening security. #Bitrefill #Bluenoroff

Keypoints

  • Bitrefill attributes the breach to North Korea-linked Bluenoroff/Lazarus based on tactics, malware, and reused IP and email indicators.
  • Attackers compromised an employee laptop, stole legacy credentials, and accessed production snapshots, databases, and some cryptocurrency wallets.
  • Approximately 18,500 purchase records with customer emails, IP addresses, and crypto payment addresses were exposed, and 1,000 records included names; decryption keys may have been obtained.
  • The intrusion exploited supplier purchasing patterns and gift card supply lines to drain inventory and hot wallets, indicating a focus on crypto and gift card theft rather than customer data theft.
  • Bitrefill reports minimal losses covered from its capital and is expanding security reviews, pen-testing, access controls, logging/monitoring, and automated shutdown mechanisms while most services return to normal.

Read More: https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/