Gold 24K AED 524.09/gUSD/AED 3.6725USDT/AED 3.6715AED/INR 25.92All live rates →

North Korean Hackers Use New ‘Durian’ Malware to Target Cryptocurrency Firms

North Korean hackers have reportedly unleashed a new malware variant called “Durian” to target South Korean cryptocurrency firms, according to a threat report by cybersecurity firm Kaspersky on May 9.

The Kimsuky hacking group, believed to be behind the attacks, utilized Durian in a series of targeted assaults on at least two crypto companies. They exploited legitimate security software exclusively used by South Korean crypto firms in what Kaspersky described as a “persistent” attack.

Durian, previously unknown, functions as an installer for a range of malware, including a backdoor named “AppleSeed,” a custom proxy tool known as LazyLoad, and other legitimate utilities like Chrome Remote Desktop. This malware offers extensive backdoor capabilities, allowing for the execution of commands, file downloads, and data exfiltration.

Kaspersky also noted the use of LazyLoad by Andariel, a sub-group within the Lazarus Group, a well-known North Korean hacking consortium. This suggests a potential connection between Kimsuky and Lazarus Group.

Lazarus Group, established in 2009, has gained notoriety as one of the most prolific crypto hacking groups. On April 29, blockchain analyst ZachXBT revealed that Lazarus had laundered over $200 million in illicit crypto between 2020 and 2023. Overall, Lazarus is accused of pilfering more than $3 billion in crypto assets over a six-year period.

In 2023 alone, Lazarus was credited with stealing over 17% of the total stolen funds, amounting to approximately $309 million. Throughout the year, more than $1.8 billion worth of crypto fell victim to hacks and exploits, as reported by Immunefi on December 28.

May 2024, Cryptoniteuae

📧 The Gulf reads Cryptonite first
Get MENA regulation moves, RWA deals and AI-money trends in one weekly brief — plus instant alerts when the MENA Regulation Tracker changes. Free, no spam.
Was this briefing useful?Thanks for the feedback!
Vaibhavv Ali
Vaibhavv Ali

Vaibhavv Ali is the founder and editor of Cryptonite (cryptonite.ae), an independent digital-asset news and analysis publication with a UAE focus. He covers virtual-asset regulation — VARA, ADGM and the UAE Central Bank — alongside real-world-asset tokenization, stablecoins and agentic AI in finance. Every Cryptonite article is human-edited and its sources are linked. He is also a celebrated speaker and host.

More articles by Vaibhavv Ali →
About  ·  Contact  ·  Privacy Policy  ·  Editorial Policy  ·  Advertise  ·  Newsletter
Follow: X  ·  LinkedIn  ·  Instagram  ·  Binance Square  ·  CoinMarketCap  ·  Gate