+更多
专家名录
唐朱昌
唐朱昌
教授,博士生导师。复旦大学中国反洗钱研究中心首任主任,复旦大学俄...
严立新
严立新
复旦大学国际金融学院教授,中国反洗钱研究中心执行主任,陆家嘴金...
陈浩然
陈浩然
复旦大学法学院教授、博士生导师;复旦大学国际刑法研究中心主任。...
何 萍
何 萍
华东政法大学刑法学教授,复旦大学中国反洗钱研究中心特聘研究员,荷...
李小杰
李小杰
安永金融服务风险管理、咨询总监,曾任蚂蚁金服反洗钱总监,复旦大学...
周锦贤
周锦贤
周锦贤先生,香港人,广州暨南大学法律学士,复旦大学中国反洗钱研究中...
童文俊
童文俊
高级经济师,复旦大学金融学博士,复旦大学经济学博士后。现供职于中...
汤 俊
汤 俊
武汉中南财经政法大学信息安全学院教授。长期专注于反洗钱/反恐...
李 刚
李 刚
生辰:1977.7.26 籍贯:辽宁抚顺 民族:汉 党派:九三学社 职称:教授 研究...
祝亚雄
祝亚雄
祝亚雄,1974年生,浙江衢州人。浙江师范大学经济与管理学院副教授,博...
顾卿华
顾卿华
复旦大学中国反洗钱研究中心特聘研究员;现任安永管理咨询服务合伙...
张平
张平
工作履历:曾在国家审计署从事审计工作,是国家第一批政府审计师;曾在...
转发
上传时间: 2024-03-19      浏览次数:411次
Lazarus APT Group Returned To Tornado Cash To Launder Stolen Funds

 

https://securityaffairs.com/160525/breaking-news/lazarus-apt-returned-tornado-cash.html

 

North Korea-linked Lazarus APT group allegedly has reportedly resumed using the mixer platform Tornado Cash to launder $23 million.

 

Blockchain cybersecurity firm Elliptic linked the theft of $112.5 million from exchange HTX, which took place in November 2023, to the North Korea’s group. Now Elliptic reported that over the past day, the group laundered more than $23 million from this attack through Tornado Cash.

 

In August 2022, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned the crypto mixer service Tornado Cash used by North Korean-linked Lazarus APT Group.

 

The mixers are essential components for cybercriminals that use them for money laundering, it was used to launder the funds stolen from the victims.

 

At the time of the announcement of the sanctions by OFAC, Tornado Cash was used to launder more than $7 billion worth of virtual currency since its creation in 2019. The Lazarus APT group laundered over $455 million stolen during the largest known virtual currency heist to date. Tornado Cash was also used to launder more than $96 million of malicious cyber actors’ funds derived from the June 24, 2022 Harmony Bridge Heist, and at least $7.8 million from the recent Nomad crypto heist. However, Tornado Cash has never interrupted its operations despite sanctions.

 

In response to the sanctions, Lazarus turned to the mixer Sinbad.io, but this service was seized by US authorities in November 2023.

 

The researchers noted that the mixer operates through smart contracts on decentralized blockchains, making it immune to seizure and shutdown such as the one that lead to the seizure of the centralized mixer Sinbad.io.

 

Lazarus Group now appear to have returned to using Tornado Cash as a way to launder funds at scale and obfuscate their transaction trail. Since March 13 2024, more than $23 million in ETH from the HTX/HECO thefts have been sent to Tornado Cash, across more than 60 transactions.” reads the report published by Elliptic.

 

This change in behavior and return to the use of Tornado Cash likely reflects the limited number of large-scale mixers now operating, thanks to law enforcement takedowns of services such as Sinbad.io and Blender.io.”

 

Cryptocurrency exchanges and financial institutions are recommended to use tools such as wallet screening solutions to prevent transactions with sanctioned entities like Tornado Cash and the Lazarus Group.