Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

North Korean Hackers Target Crypto Experts with KANDYKORN

The intrusion was first noticed when it detected an attempt to load a computer program into memory on a Mac computer.

Written By:
Dishita Malvania

Last updated: July 15, 2025 1:51 PM
Published 2023-11-02
Share
North Korean Hackers Target Crypto Experts with KANDYKORN

Elastic Security Labs revealed that a North Korean hacker group known as Lazarus employed a Python program disguised as a cryptocurrency arbitrage bot. They distributed this program through a private message on a public Discord server. They used a new kind of malware called “KANDYKORN” to target these engineers through Discord, a messaging platform.

Elastic Security Labs disclosed that the North Korean hacker group Lazarus used a Python application posing as a cryptocurrency arbitrage bot delivered via a direct message on a public Discord server, which is atypical of macOS intrusions.https://t.co/pJe5BLFQGy

— Wu Blockchain (@WuBlockchain) November 2, 2023

The intrusion was first noticed when it detected an attempt to load a computer program into memory on a Mac computer. After investigating, it stated that the attack started with a Python application pretending to be a cryptocurrency trading bot, which was sent as a direct message on a public Discord server.

“The victim believed they were installing an arbitrage bot, a software tool capable of profiting from cryptocurrency rate differences between platforms,” the researchers said. 

The group behind this attack is from North Korea (DPRK) and has also found similarities with another hacking group known as the Lazarus Group. These similarities include the techniques used, the network infrastructure, the certificates used to sign the malicious software, and custom methods of detecting Lazarus Group activities. They have given this specific intrusion the name REF7001 for tracking purposes.

Also Read: North Korean Hackers Swipe $180M in H1 2023 Crypto Heist

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Dishita Malvania - Senior crypto journalist at The Crypto Times
By Dishita Malvania
Follow:
Dishita Malvania is a Crypto Journalist with 3 years of experience covering the evolving landscape of blockchain, Web3, AI, finance, and B2B tech. With a background in Computer Science and Digital Media, she blends technical knowledge with sharp editorial insight. Dishita reports on key developments in the crypto world—including Litecoin, WazirX, Solana, Cardano, and broader blockchain trends—alongside interviews with notable figures in the space. Her work has been referenced by top digital media outlets like Entrepreneur.com, The Independent, The Verge, and Metro.co, especially on trending topics like Elon Musk, memecoins, Trump, and notable rug pulls.

Latest News

Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Sen. Gillibrand's Son Bets on Perpetual Futures With $30M Raise
Sen. Gillibrand’s Son Bets on Perpetual Futures With $30M Raise

Find Us on Socials

You may also like

Crypto Market Crash BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Crypto Market Crash: BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

North Korean IP Googled Bitcoin MVRV On Mac, Should Traders Worry

North Korean IP Googled Bitcoin MVRV On Mac, Should Traders Worry?

Chainalysis 80% of Brazil's Illicit Crypto Flows Through Just 5 Addresses

Chainalysis: 80% of Brazil’s Illicit Crypto Flows Through Just 5 Addresses

India's FIU Seeks Data on OTC Crypto Deals Above ₹9.4 Lakh

India’s FIU Seeks Data on OTC Crypto Deals Above ₹9.4 Lakh

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information