
Security firm ClearSky has published a report saying that a hacking group (likely from Eastern Europe) has stolen approximately $200 million from online cryptocurrency exchanges .Or Blatt, head of research at ClearSky, said the company has been tracking the hacking group for some time. The group is called CryptoCore and has been active since 2018.
Researchers have linked CryptoCore to at least five successful breaches and have seen attempted attacks on 10-20 exchanges.
The five confirmed victims are located in the United States, Japan and the Middle East. However, the company did not provide the names of the victims.
ClearSky says some of operations have previously been discussed in separate reports identifying the group as “Dangerous Password” and “Leery Turtle [PDF].” However, ClearSky says the group’s activities are more extensive than initially believed.
The same techniques over the last three years or so
The hacking group has been active for about two and a half years, but according to ClearSky, it has been using the same tactics all this time, with only minor variations.
ClearSky says that all attacks start with data collection. At this stage, hackers steal the necessary details to target the exchange's management, IT staff, and other employees.
The first phishing attacks are usually made on personal email accounts rather than corporate ones, as they are more likely to be less secure.
However, CryptoCore hackers will also try to target corporate emails.
“It is a matter of hours or weeks until the spear-phishing email reaches the corporate email of an exchange manager,” said ClearSky.
Hackers send the spear-phishing email and present themselves as high-ranking executives of either the organization itself or another organization with which there is collaboration.
The ultimate goal is to install malware on an employee or administrator’s computer and steal or gain access to password manager accounts. CryptoCore attackers will use these passwords to break into accounts and wallets. They will disable two-factor authentication systems and begin transferring funds from the exchange’s wallets to their own.

CryptoCore is the second organized group to repeatedly target exchanges in the past 3 years. Typically, hackers funded by the North Korean pose the biggest threat to these services.
