North Korea’s Lazarus Group poses as Fenbushi executive: SlowMist

Quick Take

  • SlowMist’s information security chief alerted that a hacker from North Korea’s Lazarus Group is posing as an executive member of asset management firm Fenbushi Capital.
  • Lazarus usually impersonates an investor to target prominent DeFi projects, SlowMist said.

The North Korea-backed cyber-hacker entity Lazarus Group is targeting LinkedIn users by impersonating an executive member of Chinese blockchain asset management firm Fenbushi Capital, security firm SlowMist said Monday.

SlowMist’s chief information security officer posted a screenshot on X that shows the scam LinkedIn user under the name “Nevil Bolson” who claimed to be the founding partner at Fenbushi. The impostor’s profile picture was taken from real Fenbushi Capital partner Remington Ong, according to 23pds.

The Block confirmed that Lazarus Group’s fake LinkedIn user page remains live at publication time. “Looking for Software developers. Please reach out to me for more discussion,” the impostor posted on LinkedIn three weeks ago.

“Lazarus would use this impostor to chat privately with their targets on LinkedIn, chatting in the name of investment, and then would say, ‘let’s set up a meeting,’” 23pds told The Block. 

SlowMist said in a blog post that Lazarus targets prominent DeFi projects, which is one of the reasons the hacker group poses as a member of an investment company. After the hackers gain the victim’s trust, Lazarus inserts malicious links that pose as a meeting link or an events page, which will launch a phishing attack when clicked.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

The SlowMist CISO told The Block that they identified “Nevil Bolson” as a part of Lazarus by comparing IP addresses on top of using the same attack strategy.

North Korea’s state-backed crypto hacker groups earned the country around 50% of its foreign currency, a large share of which was reportedly used for developing weapons of mass destruction, according to the UN Security Council.

About $1.7 billion worth of funds were stolen from the crypto space across 231 hacks, according to blockchain analytics firm Chainalysis.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Danny Park is an East Asia reporter at The Block writing on topics including Web3 developments and crypto regulations in the region. He was formerly a reporter at Forkast.News, where he actively covered the downfall of Terra-Luna and FTX. Based in Seoul, Danny has previously produced written and video content for media companies in Korea, Hong Kong and China. He holds a Bachelor of Journalism and Business Marketing from the University of Hong Kong.

Editor

To contact the editor of this story:
Adam James at
[email protected]