icon
icon
icon
icon
Upgrade
Upgrade

News /

Articles /

Bybit Hack Linked to Compromised Developer Laptop and DPRK Ties

Coin WorldThursday, Mar 6, 2025 2:44 pm ET
1min read

Safe, a prominent security firm, recently published a preliminary report revealing that the breach which led to the Bybit hack was attributed to a compromised developer laptop. The vulnerability resulted in the injection of malware, which allowed the hackers to gain unauthorized access to Bybit's systems. The perpetrators circumvented multi-factor authentication (MFA) by exploiting active amazon Web Services (AWS) tokens, enabling unauthorized access.

The breach originated from a compromised macOS workstation belonging to a Safe developer, referred to in the report as “Developer1.” On Feb. 4, a contaminated Docker project communicated with a malicious domain named “getstockprice[.]com,” suggesting social engineering tactics. Developer 1 added files from the compromised Docker project, compromising their laptop. The domain was registered via Namecheap on Feb. 2. SlowMist later identified getstockprice[.]info, a domain registered on Jan. 7, as a known indicator of compromise (IOC) attributed to the Democratic People’s Republic of Korea (DPRK).

Attackers accessed Developer 1’s AWS account using a User-Agent string titled “distrib#kali.2024.” Cybersecurity firm Mandiant, tracking UNC4899, noted that this identifier corresponds to Kali Linux usage, a toolset commonly used by offensive security practitioners. Additionally, the report revealed that the attackers used ExpressVPN to mask their origins while conducting operations. It also highlighted that the attack resembles previous incidents involving UNC4899, a threat actor associated with TraderTraitor, a criminal collective allegedly tied to DPRK.

In a prior case from September 2024, UNC4899 leveraged Telegram to manipulate a crypto exchange developer into troubleshooting a Docker project, deploying PLOTTWIST, a second-stage macOS malware that enabled persistent access. Safe’s AWS configuration required mfa re-authentication for Security Token Service (STS) sessions every 12 hours. Attackers attempted but failed to register their own MFA device. To bypass this restriction, they hijacked active AWS user session tokens through malware planted on Developer1’s workstation. This allowed unauthorized access while AWS sessions remained active.

Mandiant identified three additional UNC4899-linked domains used in the Safe attack. These domains, also registered via Namecheap, appeared in AWS network logs and Developer1’s workstation logs

Comments

Add a public comment...
Post
User avatar and name identifying the post author
moazzam0
03/06
$AMZN Big reversals on the way, most bs ever
0
Reply
User avatar and name identifying the post author
Serious_Procedure_19
03/06
$AMZN Trump presidency really hurting Amazon
0
Reply
User avatar and name identifying the post author
agnesmoralesss
03/06

Weeks ago I started my trading journey with $1000 and didn’t have much experience. After few days of consistent work and following the recommendations of Elizabeth Towles on Whatsapp +1563 279-8487,I managed to grow my account to $8850

0
Reply
User avatar and name identifying the post author
goodpointbadpoint
03/06
@agnesmoralesss How long did it take you to grow your account from $1000 to $8850, and what specific stocks or strategies did you use?
0
Reply
Disclaimer: The news articles available on this platform are generated in whole or in part by artificial intelligence and may not have been reviewed or fact checked by human editors. While we make reasonable efforts to ensure the quality and accuracy of the content, we make no representations or warranties, express or implied, as to the truthfulness, reliability, completeness, or timeliness of any information provided. It is your sole responsibility to independently verify any facts, statements, or claims prior to acting upon them. Ainvest Fintech Inc expressly disclaims all liability for any loss, damage, or harm arising from the use of or reliance on AI-generated content, including but not limited to direct, indirect, incidental, or consequential damages.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App