World Report: North Korean hackers stepping up crypto attacks

Report: North Korean hackers stepping up crypto attacks

-

- Advertisment -


SEOUL, Jan. 25 (BP) — North Korean hackers are displaying a “startup mentality” as they experiment with new methods to pull off cryptocurrency heists, a report by cybersecurity firm Proofpoint said Wednesday.

The Sunnyvale, California-based firm said that a group they identify as TA444, which overlaps with infamous hacker collective Lazarus, launched a massive wave of phishing attacks in December targeting the financial, education, government and healthcare sectors in the United States and Canada.

The group’s emails used approaches that differed from tactics researchers had previously associated with them, including efforts to gain users’ passwords and login information.

“This sprawling credential harvesting activity is a deviation from normal TA444 campaigns, which typically involve the direct deployment of malware,” the report said.

The hackers used email marketing tools to help avoid phishing filters and created content such as job offers and salary adjustments to lure targets. They also relied on social media networking service LinkedIn to engage with victims before delivering links to malware, the researchers said.

Proofpoint said the December spam wave nearly doubled the volume of emails sent by the group for the entire year.

Greg Lesnewich, senior threat researcher at Proofpoint, said in an email that TA444 has a “startup mentality” and is “testing a variety of infection chains to help expand its revenue streams.”

“This threat actor rapidly ideates new attack methods while embracing social media as part of their M.O.,” he said. “TA444 spearheads North Korea’s cashflow generation for the regime by bringing in launderable funds.”

North Korea remains under heavy international sanctions and has increasingly turned to cybercrime in an effort to finance its illicit weapons program.

The Pyongyang-affiliated Lazarus Group was behind the stunning theft of more than $600 million in cryptocurrency from an online video game network in March, according to the FBI.

On Monday, the FBI also confirmed that the Lazarus Group was responsible for a $100 million heist in June of Horizon Bridge, a crypto transfer service operated by U.S.-based Harmony blockchain.

South Korea’s National Intelligence Service said last month that North Korea had stolen cryptocurrency assets worth $1.2 billion globally since 2017, with the majority of it coming in 2022.

The spy agency warned that Pyongyang was expected to step up its efforts this year to steal sensitive intelligence and defense technology from the South.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

At least seven killed by gunman in East Jerusalem synagogue attack

World News // 4 hours ago Record rainfall paralyzes New Zealand's north island Jan. 27 (BP) -- A state...

ICC will reopen investigation into Philippines’ deadly drug war

The International Criminal Court announced that it would allow its prosecutors to reopen an investigation into...

9 Palestinians killed, many injured in Israeli raid on West Bank

Mourners carry bodies of Palestinians killed during clashes with Israeli troops in Jenin, West Bank, on...

11 killed as Russia launches new missile strikes in Ukraine

1/4 Russian strikes targeted energy infrastructure and killed 11 people on Thursday, according to Ukrainian officials. EPA-EFE/Sergey...
- Advertisement -

Germany announces treason arrest, says suspect gave info to Russia

The German Federal Public Prosecutor's Office Thursday said a second man has been arrested for alleged...

How you can Uninstall Avast From Apple pc

If you're using Avast in your Mac, you might have noticed that it might slow down any system....

Must read

At least seven killed by gunman in East Jerusalem synagogue attack

World News // 4 hours ago Record rainfall paralyzes...

ICC will reopen investigation into Philippines’ deadly drug war

The International Criminal Court announced that...
- Advertisement -

You might also likeRELATED
Recommended to you