The BitMEX security team analyzed a social engineering attack attempt involving a fake NFT project invitation and uncovered indicators of compromise, including potential attacker IP addresses and significant operational security failures by the Lazarus Group.

Claim

Quotes that support claims

Investigating this Lazarus Group campaign shows a stark contrast between their entry-level phishing strategies and advanced post-exploitation techniques. The accidental exposure of the Supabase database revealed not only their tracking methods but also significant lapses in operational security, such as the leakage of Chinese IP addresses.
The BitMEX security team says it investigated the incident, allegedly discovering new insight into the group’s inner workings — including potential IP addresses — and ‘significant lapses in operational security.’

Referenced by

Attack tactics and security response

Crypto news

Data block