BitMEX Exchange Foils Lazarus Group’s Phishing Attack, Calls Methods ’Amateurish’
BitMEX has successfully blocked a phishing attempt by the infamous North Korea-linked Lazarus Group, labeling their tactics as "amateurish." The attack, outlined in a May 30 blog post, targeted an employee through LinkedIn under the guise of a Web3 NFT partnership. The attacker tried to trick the employee into running a malicious GitHub project, a hallmark of Lazarus Group operations.
BitMEX’s security team quickly identified the obfuscated JavaScript payload and connected it to infrastructure previously linked to the group. A lapse in operational security exposed an IP address associated with North Korean activities in Jiaxing, China, NEAR Shanghai. BitMEX highlighted that Lazarus often relies on rudimentary phishing techniques to breach systems, despite being organized into subgroups with differing technical capabilities.