{"id":4263,"date":"2022-01-14T17:34:37","date_gmt":"2022-01-14T12:04:37","guid":{"rendered":"https:\/\/xiarch.com\/blog\/?p=4263"},"modified":"2022-01-14T17:35:35","modified_gmt":"2022-01-14T12:05:35","slug":"why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension","status":"publish","type":"post","link":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/","title":{"rendered":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension?"},"content":{"rendered":"\n<p><p style=\"text-align: justify;\">The North Korean attacker gang known as \u2018BlueNoroff\u2019 has been addressed the targeting cryptocurrency startups with malicious documents and fake MetaMask browser extensions.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The main motive of the gang is purely financial, but its sophistication in carrying out the objective has priory led investigators to conclude that this is a sub-group of the North Korean Lazarus group.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Although BlueNoroff has been active for several years, its structure and operation have been shrouded by mystery. A report by Xiarch researchers attempts to shed some light by using intelligence collected during the most recent activity observed, dating back to November 2021.<\/p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What are its Targets?<\/strong><\/h3>\n\n\n\n<p><p style=\"text-align: justify;\">The latest attacks are focused on cryptocurrency startups located in the US, Russia, China, India, the UK, Ukraine, Poland, Czech Republic, UAE, Singapore, Estonia, Vietnam, Malta, Germany, and Hong Kong.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"467\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1-1024x467.png\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1\" class=\"wp-image-4265\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1-1024x467.png 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1-300x137.png 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1-768x350.png 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1-1536x700.png 1536w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image1.png 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">The threat actors attempt to infiltrate the communications of these firms and map the interactions between the employees to derive potential social engineering pathways. In some cases, they do this by compromising the LinkedIn account of an employee and sharing a link to download a macro-laced document right on the platform.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">BlueNoroff uses these real discussions to name laced documents accordingly and send them to the target employee at the right time.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image2.jpg\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image2\" class=\"wp-image-4266\" width=\"524\" height=\"261\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image2.jpg 901w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image2-300x150.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image2-768x383.jpg 768w\" sizes=\"(max-width: 524px) 100vw, 524px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">To track their campaign, they include an icon from a third-party tracking service (Sendgrid) to get a notification when the victim opens the sent document. The company names and logos impersonated by BlueNoroff are shown below:<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image3.jpg\" alt=\"\" class=\"wp-image-4267\" width=\"529\" height=\"450\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image3.jpg 865w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image3-300x256.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image3-768x654.jpg 768w\" sizes=\"(max-width: 529px) 100vw, 529px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">At Xiarch, these organizations may not have been negotiated, and Sendgrid may not know was alerted that North Korean APTs are harming them.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What are the Condition chains?<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">The first infection chain uses documents that feature VBS scripts, which exploit an old remote template injection vulnerability (CVE-2017-0199).<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"393\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4-1024x393.jpg\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4\" class=\"wp-image-4271\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4-1024x393.jpg 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4-300x115.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4-768x295.jpg 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4-1536x589.jpg 1536w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image4.jpg 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">The second infection chain relies on sending an archive that contains a shortcut file and a password-protected document (Excel, Word, or PDF).<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5-1024x404.jpg\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5\" class=\"wp-image-4272\" width=\"688\" height=\"271\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5-1024x404.jpg 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5-300x118.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5-768x303.jpg 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image5.jpg 1389w\" sizes=\"(max-width: 688px) 100vw, 688px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">The LNK file that supposedly contains the password to open the document initiates a series of scripts that fetches the next-stage payload. Eventually, in both cases, a backdoor with the subsequent functionalities is dropped onto the infected machine:<\/p><\/p>\n\n\n\n<ul><li>Directory\/File manipulation<\/li><li>Process manipulation<\/li><li>Registry manipulation<\/li><li>Executing commands<\/li><li>Updating configuration<\/li><li>Stealing stored data from Chrome, Putty, and WinSCP<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Fake MetaMask steal crypto from victims<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">BlueNoroff steals user credentials that can be used for lateral movement and deeper network infiltration, while they also collect configuration files relevant to cryptocurrency software.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;In some cases where the attackers realized they had found a prominent target, they carefully monitored the user for weeks or months,&#8221; reads Xiarch report. &#8220;They collected keystrokes and monitored the user\u2019s daily operations while planning a strategy for financial theft.&#8221;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The main trick employed to steal the cryptocurrency investments is to return the core elements of wallet management browser extensions with tampered versions that are dropped on local memory.<strong>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<\/strong><\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6-1024x493.png\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6\" class=\"wp-image-4273\" width=\"587\" height=\"282\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6-1024x493.png 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6-300x144.png 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6-768x370.png 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image6.png 1486w\" sizes=\"(max-width: 587px) 100vw, 587px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">Xiarch notes that tampering with the Metamask Chrome extension requires a thorough analysis of 170,000 lines of code, indicative of the skills and determination of BlueNoroff.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Victims can only detect the extension is fake by switching the browser to Developer mode and seeing the extension source pointing to a local directory rather than the online store.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">When the target uses a hardware wallet, the actors wait for marketings and seize the quantities by changing the recipient&#8217;s address. Because they have only one possibility before the target acknowledges the infection, the actors also change the transaction amount to the maximum possible, draining the assets in one move.<\/p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Indications for attribution<\/strong><\/h3>\n\n\n\n<p><p style=\"text-align: justify;\">On the element of attribution, Xiarch researchers convey seeing overlappings and parallels between PowerShell scripts and backdoors operated in the most delinquent and past movements.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"274\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7-1024x274.jpg\" alt=\"Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7\" class=\"wp-image-4274\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7-1024x274.jpg 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7-300x80.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7-768x205.jpg 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7-1536x411.jpg 1536w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-image7.jpg 1582w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">Moreover, the C2 address acquisition method is identical to the 2016 attacks, using a hardcoded DWORD matter to select an IP address through XORing. Ultimately, the metadata on the Windows shortcut files settled as part of the dual infection chain containing Korean characters.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The North Korean attacker gang known as \u2018BlueNoroff\u2019 has been addressed the targeting cryptocurrency startups with malicious documents and fake MetaMask browser extensions. The main motive of the gang is purely financial, but its sophistication in carrying out the objective has priory led investigators to conclude that this is a sub-group of the North Korean [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4275,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.11 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited\" \/>\n<meta property=\"og:description\" content=\"The North Korean attacker gang known as \u2018BlueNoroff\u2019 has been addressed the targeting cryptocurrency startups with malicious documents and fake MetaMask browser extensions. The main motive of the gang is purely financial, but its sophistication in carrying out the objective has priory led investigators to conclude that this is a sub-group of the North Korean [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiarch Solutions Private Limited\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xiarch\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-14T12:04:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-01-14T12:05:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-featuredimage.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Xiarch Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@xiarch\" \/>\n<meta name=\"twitter:site\" content=\"@xiarch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Xiarch Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\"},\"author\":{\"name\":\"Xiarch Security\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\"},\"headline\":\"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension?\",\"datePublished\":\"2022-01-14T12:04:37+00:00\",\"dateModified\":\"2022-01-14T12:05:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\"},\"wordCount\":661,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\",\"url\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\",\"name\":\"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#website\"},\"datePublished\":\"2022-01-14T12:04:37+00:00\",\"dateModified\":\"2022-01-14T12:05:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/xiarch.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/xiarch.com\/blog\/#website\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"name\":\"Xiarch Solutions Private Limited\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/xiarch.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\",\"name\":\"Xiarch\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"contentUrl\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"width\":300,\"height\":300,\"caption\":\"Xiarch\"},\"image\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/xiarch\/\",\"https:\/\/twitter.com\/xiarch\",\"https:\/\/www.linkedin.com\/company\/xiarch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\",\"name\":\"Xiarch Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"caption\":\"Xiarch Security\"},\"sameAs\":[\"https:\/\/xiarch.com\/blog\/\"],\"url\":\"https:\/\/xiarch.com\/blog\/author\/vector\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/","og_locale":"en_US","og_type":"article","og_title":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited","og_description":"The North Korean attacker gang known as \u2018BlueNoroff\u2019 has been addressed the targeting cryptocurrency startups with malicious documents and fake MetaMask browser extensions. The main motive of the gang is purely financial, but its sophistication in carrying out the objective has priory led investigators to conclude that this is a sub-group of the North Korean [&hellip;]","og_url":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/","og_site_name":"Xiarch Solutions Private Limited","article_publisher":"https:\/\/www.facebook.com\/xiarch\/","article_published_time":"2022-01-14T12:04:37+00:00","article_modified_time":"2022-01-14T12:05:35+00:00","og_image":[{"width":1000,"height":525,"url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2022\/01\/Why-BlueNoroff-Attackers-Hijack-Crypto-by-utilizing-Fake-MetaMask-Extension-featuredimage.jpg","type":"image\/jpeg"}],"author":"Xiarch Security","twitter_card":"summary_large_image","twitter_creator":"@xiarch","twitter_site":"@xiarch","twitter_misc":{"Written by":"Xiarch Security","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#article","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/"},"author":{"name":"Xiarch Security","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c"},"headline":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension?","datePublished":"2022-01-14T12:04:37+00:00","dateModified":"2022-01-14T12:05:35+00:00","mainEntityOfPage":{"@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/"},"wordCount":661,"commentCount":0,"publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"articleSection":["Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/","url":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/","name":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension? - Xiarch Solutions Private Limited","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/#website"},"datePublished":"2022-01-14T12:04:37+00:00","dateModified":"2022-01-14T12:05:35+00:00","breadcrumb":{"@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/xiarch.com\/blog\/why-bluenoroff-attackers-hijack-crypto-by-utilizing-affected-metamask-extension\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiarch.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Why BlueNoroff Attackers Hijack Crypto by utilizing Affected MetaMask Extension?"}]},{"@type":"WebSite","@id":"https:\/\/xiarch.com\/blog\/#website","url":"https:\/\/xiarch.com\/blog\/","name":"Xiarch Solutions Private Limited","description":"","publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiarch.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiarch.com\/blog\/#organization","name":"Xiarch","url":"https:\/\/xiarch.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","contentUrl":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","width":300,"height":300,"caption":"Xiarch"},"image":{"@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/xiarch\/","https:\/\/twitter.com\/xiarch","https:\/\/www.linkedin.com\/company\/xiarch"]},{"@type":"Person","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c","name":"Xiarch Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","caption":"Xiarch Security"},"sameAs":["https:\/\/xiarch.com\/blog\/"],"url":"https:\/\/xiarch.com\/blog\/author\/vector\/"}]}},"_links":{"self":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4263"}],"collection":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/comments?post=4263"}],"version-history":[{"count":2,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4263\/revisions"}],"predecessor-version":[{"id":4277,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/4263\/revisions\/4277"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media\/4275"}],"wp:attachment":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media?parent=4263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/categories?post=4263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/tags?post=4263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}