Security News > 2023 > November > US seizes Sinbad crypto mixer used by North Korean Lazarus hackers
The U.S. Department of the Treasury has sanctioned the Sinbad cryptocurrency mixing service for its use as a money-laundering tool by the North Korean Lazarus hacking group.
Today, the Treasury's Office of Foreign Assets Control has sanctioned Sinbad.io for its alleged use by North Korean hackers who have performed large-scale crypto heists, leading to hundreds of millions of dollars in losses.
Lazarus is a notorious North Korean hacking group known for its phishing attacks, fake employee recruitments, and exploiting blockchain vulnerabilities to steal millions in crypto, including $620 million from Axie Infinity, $100 million from Harmony Horizon, the Atomic Wallet hacks, and $37 million from CoinsPaid.
According to the Treasury Department, Sinbad was used to mix most of the stolen funds from the Atomic Wallet, Axie Infinity, and Horizon hacks.
In addition to sanctioning the crypto mixer, the domain for the Sinbad website has been seized in an international law enforcement operation conducted by the U.S., Netherlands, and Poland.
In 2022, OFAC sanctioned the Tornado Cash mixer for its use by North Korean hackers to launder stolen funds.
News URL
Related news
- North Korean hackers employ new tactics to compromise crypto-related businesses (source)
- North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS (source)
- North Korean hackers use new macOS malware against crypto firms (source)
- US sanctions crypto exchanges used by Russian ransomware gangs (source)
- North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- Notorious Hacker Group TeamTNT Launches New Cloud Attacks for Crypto Mining (source)
- US says Chinese hackers breached multiple telecom providers (source)
- North Korean govt hackers linked to Play ransomware attack (source)
- North Korean hackers pave the way for Play ransomware (source)