Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ How a Fake Job Offer Took Down the World's Most Popular Crypto Game

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š How a Fake Job Offer Took Down the World's Most Popular Crypto Game


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: slashdot.org

An anonymous reader quotes a report from The Block: Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. The Block can now reveal that a fake job ad was Ronin's undoing. According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist. Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn. After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package. The fake "offer" was delivered in the form of a PDF document, which the engineer downloaded -- allowing spyware to infiltrate Ronin's systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network -- leaving them just one validator short of total control. [...] In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) -- a group set up to support the gaming ecosystem -- to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021. [...] A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100. Sky Mavis declined to comment on how the hack was carried out when reached. Earlier today, ESET Research published an investigation showing that North Korea's Lazarus had abused LinkedIn and WhatsApp by posing as recruiters to target aerospace and defense contractors. But the report did not tie that technique to the Sky Mavis hack. The Block notes that Axie Infinity "boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year -- although both numbers have since plummeted." Users affected by the exploit will be reimbursed via the company's funds, along with the $150 million it raised in a round led by Binance in early April. "The company said recently that it would begin returning funds to users on June 28," adds the report.

Read more of this story at Slashdot.

...



๐Ÿ“Œ How a Fake Job Offer Took Down the World's Most Popular Crypto Game


๐Ÿ“ˆ 83.19 Punkte

๐Ÿ“Œ Job Scamsโ€”How to Tell if that Online Job Offer is Fake


๐Ÿ“ˆ 34.96 Punkte

๐Ÿ“Œ Most of the world's most popular passwords can be cracked in under a second


๐Ÿ“ˆ 29.76 Punkte

๐Ÿ“Œ The Worldโ€™s Most Popular Coding Language Happens to be Most Hackersโ€™ Weapon of Choice


๐Ÿ“ˆ 29.76 Punkte

๐Ÿ“Œ Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ How cyber criminals stole 600 million USD using LinkedIn, fake job offer and malicious PDF


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ A fake job offer via LinkedIn allowed to steal $540M from Axie Infinity


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ Hackers Steal $540 Million From Axie Infinity Using a Fake Job Offer on LinkedIn


๐Ÿ“ˆ 26.5 Punkte

๐Ÿ“Œ Police took down DarkMarket, the worldโ€™s largest darknet marketplace


๐Ÿ“ˆ 26.34 Punkte

๐Ÿ“Œ Google: You get crypto, you get crypto, almost everyone gets email crypto!


๐Ÿ“ˆ 24.63 Punkte

๐Ÿ“Œ Twitter to take down fake accounts to please Elon Musk and his $44 billion offer


๐Ÿ“ˆ 24.46 Punkte

๐Ÿ“Œ Survey: JavaScript is the Most-Used Language, But Java is the Most Popular


๐Ÿ“ˆ 24.04 Punkte

๐Ÿ“Œ North Korean hackers target crypto experts with fake Coinbase job offers


๐Ÿ“ˆ 23.62 Punkte

๐Ÿ“Œ North Korean hackers target crypto experts with fake Coinbase job offers


๐Ÿ“ˆ 23.62 Punkte

๐Ÿ“Œ Lazarus Lures Aspiring Crypto Pros With Fake Exchange Job Postings


๐Ÿ“ˆ 23.62 Punkte

๐Ÿ“Œ Hackers use fake crypto job offers to push info-stealing malware


๐Ÿ“ˆ 23.62 Punkte

๐Ÿ“Œ Beware: Fake Facebook Job Ads Spreading 'Ov3r_Stealer' to Steal Crypto and Credentials


๐Ÿ“ˆ 23.62 Punkte

๐Ÿ“Œ FBI take Down the Most Popular Dark Web Search Site DeepDotWeb for Money Laundering


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ 4chan Harassment Prompts Maintainer Of Most Popular Audacity Fork to Step Down


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ iOS 13 Breaks Down Some of the Most Popular iPhone Games Right Now


๐Ÿ“ˆ 23.29 Punkte

๐Ÿ“Œ Just give up: 123456 is still the world's most popular password


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Worldโ€™s most popular email server praised as โ€˜near-impenetrableโ€™


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Wireshark 2.0.5 Released as the World's Most Popular Network Protocol Analyzer


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Wireshark 2.2.0 Is Out as the World's Most Popular Network Vulnerability Scanner


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Just give up: 123456 is still the world's most popular password


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Worldโ€™s most popular email server praised as โ€˜near-impenetrableโ€™


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ The worldโ€™s most popular YouTube video has been hacked


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ AirPods, the worldโ€™s most popular wireless headphones, are getting even better


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Top 10 Most Popular Search Engines In The World


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ FreeNAS 10, Worldโ€™s Most Popular Software-Defined Storage OS, Gets New Beta


๐Ÿ“ˆ 22.6 Punkte

๐Ÿ“Œ Wireshark 2.0.5 Released as the World's Most Popular Network Protocol Analyzer


๐Ÿ“ˆ 22.6 Punkte











matomo