Cybersecurity firm Hudson Rock has identified a device infected with LummaC2 malware, linked to a North Korean state-sponsored hacking group involved in the $1.4 billion Bybit cryptocurrency exchange theft. The device, used to build the attack infrastructure, contained credentials for domains registered to impersonate Bybit. It was equipped with development tools and communication apps, indicating its role in phishing operations. This finding sheds light on the internal mechanisms of North Korean hacking activities.