US and Korean Agencies Issue Warning on North Korean Cyber-Attacks

US and South Korean security officials have jointly issued a warning about North Korea’s use of social engineering tactics in cyberattacks.

The document was released Thursday by the Federal Bureau of Investigation (FBI), the US State Department, the National Security Agency (NSA), the South Korean National Intelligence Service (NIS), the National Police Agency (NPA) and police. Ministry of Foreign Affairs (Ministry of Foreign Affairs).

The report highlights the efforts of state-sponsored cyber attackers to exploit computer networks on a global scale, specifically targeting individuals working in research centers, think tanks, academic institutions, and news organizations.

The advisory identifies multiple North Korean cyber actors including Kimsuky, Thallium, APT43, Velvet Chollima, and Black Banshee. These utilize spear-phishing campaigns posing as journalists, academics, or individuals with credible ties to the North Korean policy community.

Read more about Kimsuky: North Korean APT Kimsuky Launches Global Spear Phishing Campaign

These attackers use social engineering techniques to gain unauthorized access to a target’s personal documents, research, and communications. This will allow us to gather information on geopolitical events, foreign policy strategies and diplomatic efforts, further enhancing North Korea’s interests.

Julia O’Toole, CEO of MyCena Security Solutions, said: “This alert from the US and South Korea highlights how cybercriminals are using spear phishing to steal credentials from people and obtain highly sensitive information. I am highlighting whether it is there, ”he commented.

“Once criminals secure these credentials, they can log into a target’s work email account and steal military and aerospace information that can be used to advance their own programs.”

He added that connections between attacks are often overlooked, which increases their effectiveness. Many people don’t realize that seemingly harmless phishing emails can ultimately help gather intelligence for North Korea’s military plans. However, in today’s cyber environment, such coordinated attacks are prevalent.

“These spear-phishing attacks are aimed at stealing user logins and passwords, so the best defense is to remove them from the user’s knowledge,” O’Toole added.

“If an organization generates strong, random, independent passwords for each application, encrypts them, and distributes them to employees, users can see, know, enter, and give away passwords through phishing and web spoofing scams.” This makes employees invulnerable to spear-phishing attacks.”

The Joint Recommendation encourages individuals who suspect they have been targeted to report the incident to the appropriate authorities. The paper’s publication comes after the United States imposed sanctions on four entities and one individual who were generating income and conducting malicious cyber activity in clandestine ways to support the North Korean government. rice field.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *