N. Korea Could Expand Cyber Espionage Activities

North Korea's nation state hackers have shown no limits in what they will target, from a Hollywood entertainment company to a Bangladeshi bank

Divining a method to the madness is key to warning potential victims. Analysts say that foreign corporations and defectors have been high on the list of Pyongyang’s potential targets. On New Year’s Day, North Korean dictator Kim Jong Un delivered his annual address, telling North Koreans, and the world, what would preoccupy his reclusive regime’s time in the coming months.

The message was clear: with its nuclear weapons program well underway, Pyongyang would continue to try to develop its anemic economy.

“The might of the independent socialist economy should be further strengthened,” he said. By 2020, according to its national economic development plan, North Korea wants to make advances in key sectors like coal, agriculture, and machinery, and time is running out.

North Korea’s cyber operatives have long known how to turn a profit, with one regime-linked group alone reportedly responsible for millions of dollars in bank heists.  Now, in the face of stifling international sanctions, the Hermit Kingdom’s hackers could be more important to the regime than ever.

CrowdStrike says hacking operations could be crucial to helping Kim meet his 2020 goal, and that his speech is a public hint of what’s to come.

“We think that there is going to be a lot more commercial targeting by North Korea,” Adam Meyers, CrowdStrike’s vice president of intelligence, told CyberScoop. “We’ve seen lures and we’ve seen an increased pace of activity out of North Korea.”

In other words, North Korea could take a page out of a playbook long associated with Chinese hackers: steal data from foreign companies to boost the domestic economy. There already have been quiet signs that this is happening.
Last year, Egyptian company Orascom Telecom Media and Technology, which runs a joint-venture mobile phone business with the North Korean government, was hacked. 

The venture competes with a state-run service known as Byol, providing an incentive for Pyongyang’s computer operatives to go after the company’s proprietary data. CrowdStrike believes the culprit is part of a suspected North Korean group it calls Ricochet Chollima, which traditionally has focused on espionage in South Korea.

In another example of economically-motivated activity, North Korea-linked hackers have in recent months tried to breach a Western manufacturing company’s network, CrowdStrike said. Analysts at cybersecurity company Symantec also expect suspected North Korean hackers to continue to conduct economic espionage.

“Over the years we’ve realised that one shouldn’t put anything outside of the purview of Lazarus,” said Symantec technical director Vikram Thakur, using an industry term for a broad set of hackers the US officials have tied to Pyongyang. North Korea has denied it engages in the extensive and destructive malicious cyber activity for which the US government has blamed Pyongyang.

However, stealing proprietary data is one thing; turning that data into a competitive company is quite another. And unlike China, the second largest economy in the world, North Korea’s frail economy makes that difficult.

“Their ability to turn stolen intellectual property around into a usable product is very limited,” said Priscilla Moriuchi, director of strategic threat development at cyber-intelligence company Recorded Future. “So my sense is that the goal in targeting companies would be to monetise information that they’ve gained, unless it’s a few specific sectors.”

Whether or not they are contributing to national economic development goals, the hunt for money drives much of what North Korean cyber personnel do, according to Moriuchi. Each computer operative is responsible for bringing in a certain amount of money each year, she said, resulting in plenty of “day-to-day, low-level cybercrime.”

Researchers say the North Korean government has plenty of assets abroad to enhance its criminal activity. The regime has been dubbed “the Soprano state” because of a longstanding overseas network of criminal activities for raising cash, from narcotics to counterfeiting, said Tom Creedon, senior managing director for East Asia Pacific at LookingGlass Cyber Solutions. Over the last decade or so, the North Koreans have likely tapped that network, sometimes using front companies, to support malicious cyber activity as another means of generating revenue, he said.

While financially-motivated hacking continues, evidence suggests that malware-based surveillance of North Korean defectors does too.

Days before Kim delivered his New Year’s address, South Korean officials revealed that hackers had broken into a database of information on defectors, stealing names, addresses, and dates of birth on nearly 1,000 people. There is no public forensic evidence pointing to who committed the hack; South Korean authorities haven’t named a suspect.

But there is evidence North Korea has used its cyber capabilities to spy on some of the estimated 31,000 defectors living in South Korea. South Korean officials and the Ministry of Unification overseeing the breached agency “conducted a thorough inspection to prevent the spread of similar hacking cases” after that intrusion, a ministry official told CyberScoop.
Such measures can’t prevent hackers from training their sights on those who work on North Korean defector issues, and there is some evidence that is happening.

Simon Choi, a South Korea-based cybersecurity analyst, said he recently discovered a phishing lure from someone posing as a Ministry of Unification official. The perpetrator, he said, used a vulnerability in Daum Mail, a Korean-language email service.
Choi told CyberScoop he has seen evidence of hackers targeting South Korean reporters who cover defectors as a possible means of gathering information about the refugees.

Choi blamed an “NK hacker” for the lure, though CyberScoop could not independently confirm that the activity emanated from North Korea. CrowdStrike recently warned customers about a similarly named file that used Daum Mail as command and control, Meyers said.

The company has tied that activity to another suspected North Korean hacking group it tracks as Velvet Chollima.

As the ways in which Pyongyang can use cyber operations to support its domestic and foreign policy goals grow, so, too, do the potential targets. “They’ve been extremely adaptable and innovative,” said Moriuchi, of Recorded Future.

CyberSecoop:

You Might Also Read:

North Korea Is Using The Internet Like The Mafia:

 

« Britain Aims To Lead In CyberSecurity
President Putin Wants A National AI Strategy »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

PhishLine

PhishLine

PhishLine helps Information Security Professionals meet and overcome the increasing challenges associated with social engineering and phishing.

Critifence

Critifence

Critifence provides unique Cyber Security solutions designed for Critical Infrastructure, SCADA and Industrial Control Systems.

CERT-PH

CERT-PH

CERT-PH is the National Computer Emergency Response Team and the highest body for cybersecurity related activities in the Philippines.

SaltStack

SaltStack

SaltStack develops award-winning intelligent IT automation software. We help businesses more efficiently secure and manage all aspects of their digital infrastructure.

RFA

RFA

RFA is an institutional-quality IT, financial cloud and cyber-security services provider to the financial service and investment management sector.

Datplan

Datplan

Datplan offers a software solution that gives an overview of 8 key cyber risk areas, their threats, and risk management steps.

DataViper

DataViper

Data viper is a threat intelligence platform designed for organizations, investigators, and law enforcement.

AlertSec

AlertSec

AlertSec Ensure is a U.S. patented technology that allows you to educate, verify and enforce encryption compliance of third-party devices.

Schweitzer Engineering Laboratories (SEL)

Schweitzer Engineering Laboratories (SEL)

SEL specializes in creating digital products and systems that protect, control, and automate power systems around the world.

Otorio

Otorio

OTORIO delivers industrial cybersecurity and digital risk-management solutions and services. We help our customers to keep their revenue-generating operations resilient, efficient, and safe.

Torq

Torq

Torq's no-code automation modernizes how security & operations teams work with easy workflow building, limitless integrations and numerous pre-built templates.

Cyber Suraksa

Cyber Suraksa

We make security simple and hassle-free by offering a sustained and secure IT environment with next-gen cybersecurity solutions through a scalable security-as-a-service model.

Gilsbar

Gilsbar

For more than half a century, Gilsbar has offered insurance service solutions and support for businesses and their employees.

SphereX Technologies

SphereX Technologies

SphereX is the first on-chain security solution for Web3 applications.

Awareness Software Limited (ASL)

Awareness Software Limited (ASL)

As Hosting Specialists, Awareness Software offer practical and affordable hosting solutions including backup and disaster recovery and a range of cybersecurity services.

Orca Tech

Orca Tech

Orca Tech brings together a portfolio of complimentary vendor in the IT security industry to help provide a complete solution to meet the requirements of our Partners across all sectors.