
US and South Korean cybersecurity and intelligence agencies warn in joint advisory that North Korean state-sponsored hackers are conducting ransomware attacks against medical facilities and critical infrastructure to fund illegal activities bottom.
The attack, which demands a cryptocurrency ransom in exchange for regaining access to encrypted files, is designed to support North Korea’s state-level priorities and objectives.
This “includes cyber operations targeting the U.S. and South Korean governments. Specific targets include the Department of Defense Information Network and Defense Industrial Base member networks,” the official said.
North Korean attackers have carried out espionage, financial theft and cryptojacking operations for years, including the infamous WannaCry ransomware attack in 2017 that infected hundreds of thousands of machines in more than 150 countries. has been involved in
Since then, the North Korean nation-state crew has dabbled in multiple ransomware strains such as VHD, Maui and H0lyGh0st to generate a steady stream of illicit revenue for the sanctioned regime.
Attackers have been known to operate under the identities of third-party foreign affiliates to conceal their involvement, as well as to procure infrastructure through cryptocurrencies generated through their criminal activities.
The attack chain launched by the hacking crew exploited known security flaws in Apache Log4j, SonicWall, and TerraMaster NAS appliances (e.g. CVE 2021-44228, CVE-2021-20038, and CVE-2022-24990). to get initial access. Track through reconnaissance, lateral movement, and ransomware deployment.
In addition to using privately-developed ransomware, attackers have been observed using commercial tools such as BitLocker, DeadBolt, ech0raix, Jigsaw, and YourRansom to encrypt files. It even impersonates other ransomware groups such as REvil.
As a mitigation, agencies should implement the principle of least privilege, disable unnecessary network device management interfaces, enforce multi-layered network segmentation, require phishing-resistant authentication controls, and maintain regular data backups. We encourage organizations to do so.
The alert comes as a new United Nations report finds that North Korean hackers have stolen record-breaking virtual assets estimated to be worth between $630 million and more than $1 billion in 2022. rice field.
According to a report reviewed by the Associated Press, attackers are using increasingly sophisticated techniques to gain access to digital networks involved in cyberfinance and provide information that could help North Korea’s nuclear and ballistic missile programs to the government. , companies, and individuals. .
In addition, Kimsuky, Lazarus Group, and Andariel are all part of the Reconnaissance General Bureau (RGB), a revenue generation and Information solicitation Something of value to the Hermit Kingdom.