---
title: "Hackers, North Korea, utilising 500 phishing, steal NFTs."  
description: "One of the tactics used was the use of \"malicious Mints,\" which deceived the victims into believing they were minting a real NFT by linking their wall"  
author: "Muskan Singh"  
published: 2022-12-27  
canonical: https://www.mindstick.com/news/2647/hackers-north-korea-utilising-500-phishing-steal-nfts  
category: "cryptocurrency"  
tags: ["database security", "technology", "technology news", "cryptocurrency", "hackers"]  
reading_time: 2 minutes  

---

# Hackers, North Korea, utilising 500 phishing, steal NFTs.

According to a recent revelation, North Korean hackers associated with the [cybercrime](https://www.mindstick.com/articles/279778/how-businesses-can-protect-themselves-from-cybercrime) organisation 'Lazarus Group' are behind a huge phishing campaign that targets investors in non-fungible tokens [*(NFTs)*](https://www.mindstick.com/news/2605/visa-intends-to-provide-self-controlled-cryptocurrency-wallets-for-auto-bill-payments) and uses 500 phishing domains to trick victims.

Cointelegraph cited the research as claiming that the **tactics employed by the North Korean Advanced Persistent Threat (APT) groups to divert NFT investors from their NFTs include the [deployment](https://www.mindstick.com/articles/325966/process-of-application-development-and-deployment) of bogus websites** that imitate various NFT-related platforms and projects.

One of these phoney websites claimed to be a World Cup initiative, and others mimicked well-known NFT marketplaces like OpenSea, X2Y2, and Rarible. One of the tactics used was the use of 'malicious Mints,' which deceived the victims into believing they were minting a real NFT by linking their wallet to the website.

The analysis also revealed that many phishing websites used the same Internet Protocol (IP), with 320 NFT phishing websites using a distinct IP and 372 NFT phishing websites sharing a same IP.

Other phishing methods employed included capturing and saving visitor data to external websites, [as well as](https://www.mindstick.com/interview/2481/can-you-write-a-java-class-that-could-be-used-both-as-an-applet-as-well-as-an-application) adding images to the projects that were being targeted.

According to the research, one phishing address alone managed to obtain 1,055 NFTs and profit [**300 Ethereum**](https://www.mindstick.com/news/2543/hong-kong-s-anti-money-laundering-law-has-been-modified-to-include-cryptocurrency) (ETH), totaling $367,000. According to Cointelegraph, among these phoney websites are several that pose as World Cup projects and others that seem like well-known NFT marketplaces like OpenSea, X2Y2, and Rarible.

\
**On December 22, [South Korea](https://www.mindstick.com/news/4087/south-korea-s-morphing-wheel-could-revolutionize-robotics)'s National [Intelligence](https://www.mindstick.com/articles/85716/5-predictions-for-artificial-intelligence-in-2019) Service (NIS) revealed that [North Korea](https://answers.mindstick.com/qa/99129/why-did-north-korea-fire-two-ballistic-missiles-toward-the-east-sea) has stolen cryptocurrencies worth $620 million** alone this year. According to Cointelegraph, the [National Police](https://answers.mindstick.com/qa/51830/india-s-first-ever-national-police-museum-will-establish-in-which-city) Agency of Japan sent a warning to the country's crypto-asset [enterprises](https://answers.mindstick.com/qa/44880/who-is-the-minister-of-heavy-industries-and-public-enterprises) in October, advising them to be aware of the North Korean hacking outfit.

---

Original Source: https://www.mindstick.com/news/2647/hackers-north-korea-utilising-500-phishing-steal-nfts

Copyright © MindStick Software Pvt. Ltd. This Markdown version is provided for developers, AI systems, and offline reading.
