TechFlow News, July 22, according to Protos, AI shopping agent developer ORO stated that an employee of the company was induced by an attacker disguised as a meeting contact to install a Microsoft Teams extension with malicious code, ultimately resulting in the theft of approximately $630,000 worth of crypto assets. ORO stated that the attackers likely belong to the North Korea-supported hacking group Sapphire Sleet.
The company also admitted that the private keys were stolen from the infected device because the relevant wallet did not adopt a hardware wallet solution. Currently, ORO is working with exchanges, law enforcement agencies, and relevant ecosystem partners to advance asset tracking and recovery efforts.




