N. Korea Will Unleash Cyber Attacks On The US

As tensions rise over North Korea's potential nuclear missile threat, US officials and outside experts are increasingly concerned the rogue regime will respond to international pressure by lashing out with a weapon it has already mastered.

The concern is cyber-attacks that can disable corporate networks, steal money from banks and potentially disrupt critical infrastructure.

In the best known incident in 2014, US intelligence officials say, North Korean hackers attacked Sony Pictures, destroying corporate computers and disclosing sensitive company data. The US accused North Korea of carrying it out in response to a film lampooning North Korean leader Kim Jong-un.

American intelligence officials have long ranked North Korea as one of the world's more dangerous cyber actors, trailing only Russia, China and Iran among US adversaries in its ability to inflict damage via computer networks.

Experts say North Korea could deploy the same techniques to inflict harm not just on one company, but on the American economy.

"We've been worried for some time that one of the ways that North Korea can retaliate against further escalation of tensions is via cyber, and particularly attacks against our financial sector," said Dmitri Alperovitch, co-founder of Crowdstrike, a cyber-security firm. "This is something they have really perfected as an art against South Korea."

US law enforcement and homeland security officials said in a June 13 analysis that they believe North Korea is targeting the media, aerospace, financial and critical infrastructure sectors in the United States.

"North Korea is capable of deploying malicious cyber capabilities, as they previously demonstrated in the Sony intrusions," one US intelligence official said. Intelligence officials say that while the US has cyber-offensive capabilities to retaliate, it remains vulnerable to attacks.

Some attacks are already underway. In June, the Department of Homeland Security published a warning about a North Korea hacking group it dubbed "Hidden Cobra," referred to by some researchers as "Lazarus."

"Since 2009, Hidden Cobra actors have leveraged their capabilities to target and compromise a range of victims," the warning said. "Some intrusions have resulted in the exfiltration of data while others have been disruptive in nature."

In December, the Hidden Cobra group was named a prime suspect in a theft of $81 million from the Bangladesh central bank. That's part of a string of cyber operations that officials believe were designed to raise money for the regime and its weapons programs.

"They've added cyber-crime to their portfolio of illicit activity that they have engaged in to raise money for the regime," said Juan Zarate, an NBC News analyst who is a former top Treasury official, National Security Council staffer and deputy national security advisor.

"They're absolutely stealing money through these cyber capabilities," said John Hultquist, who leads the intelligence team at FireEye, a cyber security firm.

"They're also stealing defense information. So, a decade of targeting defense contractors worldwide, may have helped in some way in gathering enough information to at least speed up their [nuclear weapons] process."

Some researchers have linked North Korea to the WannaCry ransomware attack, an outbreak of malware in May reported to have infected more than 230,000 computers in over 150 countries, making data irretrievable in many cases. But the links are not clear enough for the US to have publicly accused North Korea of involvement, multiple officials and private sector analysts told NBC News.

Kim Heung-Kwang, a former North Korean computer expert who defected to the south in 2004, told NBC News in an interview in Seoul that the North has trained thousands of military hackers capable of inflicting damage on South Korean and Western infrastructure.

"North Korea is able to use its cyber army to attack South Korea and the US," but the lack of Internet connectivity in North Korea makes it hard for the US to retaliate, he said.

FireEye has documented a number of distributed denial-of-service (DDoS) attacks on South Korean organisations and others that appear to be connected to North Korea.

For example, the firm said, in March 2011, suspected North Korean actors conducted DDoS attacks on the South Korean government, military infrastructure and a US military base in South Korea.

In December 2014, the South Korean government reported that power plants operated by Korea Hydro and Nuclear Power were targeted with wiper malware, potentially linked to North Korean actors.

While the attacks were not believed capable of affecting the function of nuclear plants, "they could create a sense of panic by altering the function of non-operational networks, hijacking social media accounts associated with critical infrastructure, or spreading alarming SMS messages during a time of armed conflict," FireEye said.

Not every expert is convinced that North Korea poses a major cyber threat.

"It's mostly data disruption," said James Lewis, a specialist at the Center for Strategic and International Studies. "The people who haven't done a good job defending themselves are the ones who get whacked. Companies or agencies that haven't protected their data or backed it up."

But Kim Heung-Kwang, who taught computer science in North Korea for 20 years before escaping 13 years ago, said North Korean hackers are working every day to perfect new techniques.

"They work hard to survive and do not give up," he said. "If they don't give up, maybe someday they might succeed."

NBC:

You Might Also Read:

NHS Cyberattack Was 'launched from N. Korea':

Can US Cyber Weapons Stop N. Korea’s Nuclear Missiles?:

N. Korea Threatens The World With Cyberwarfare - Not Nuclear Missiles:

 

« Can Tech Solve The Brexit Border Puzzle?
Fighting Digital Crime: Evolving Police Methods »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

CSA Events

CSA Events

Cloud Security Alliance conducts a series of conferences around the world. This listing provides a link to details of upcoming events.

CybergymIEC

CybergymIEC

CybergymIEC is a global leader in cyber defense solutions and training services.

Custodio Technologies

Custodio Technologies

Custodio Technologies was established as a Singaporean R&D Centre of Israel Aerospace Industries (IAI) in order to spearhead R&D activities in the field of cyber early warning.

Serverless Computing

Serverless Computing

Serverless Computing London will help architects, developers and CIOs decide on the best path to a more efficient, scalable and secure computing future.

CSIRT-IE

CSIRT-IE

CSIRT-IE is the body within the NCSC that provides assistance to constituents in responding to cyber security incidents at a national level for Ireland.

Ritz

Ritz

Ritz is the largest holistic pure-play cyber security solutions provider in Myanmar.

CICRA

CICRA

CICRA is Sri Lanka's pioneering cyber security training and consultancy provider.

Syskode Technologies

Syskode Technologies

Sykode Technologies is a next-generation global technology company offering an integrated portfolio of advisory services, products and solutions in areas including AI, IoT and Cyber Security.

Quantum Security

Quantum Security

Quantum's game-changing approach to cybersecurity brings you performance and peace-of-mind, with a raft of additional benefits: it's non-proprietary, comprehensive, scalable, and affordable.

Fastcomcorp

Fastcomcorp

Fastcomcorp offers a world-class proactive cyber security defense and risk management consulting. Including Darkweb monitoring and posture assessments.

SkyePoint Decisions

SkyePoint Decisions

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider.

VikingCloud

VikingCloud

VikingCloud (formerly Sysnet Global Solutions) offers organizations an integrated cybersecurity and compliance solution to make informed, predictive, and cost-effective risk mitigation and prevention

Raman Power Technologies

Raman Power Technologies

Raman Power Technologies focus on bringing value and solving business challenges through the delivery of modern IT services and solutions including cybersecurity.

FTx Identity

FTx Identity

FTx Identity is the world's most advanced age verification technology (AVT) and identity management system.

Cyderes

Cyderes

Cyderes (Cyber Defense and Response) is a global, pure-play, full life-cycle cyber security services provider formed from the merger of Herjavec Group and Fishtech Group in 2022.

Barrier Networks

Barrier Networks

Barrier Networks are a Cyber Security Managed Service Provider that specialises in Network and Application security.