DPRK hacking groups breach South Korean defense contractors

  • April 23, 2024
  •  
  • 12:56 PM
  •  
  • 0

DPRK hacking groups breach South Korean defense contractors

The National Police Agency in South Korea issued an urgent warning today about North Korean hacking groups targeting defense industry entities to steal valuable technology information.

The police discovered several instances of successful breaches of defense companies in South Korea involving the hacking groups Lazarus, Andariel, and Kimsuky, all part of the North Korean hacking apparatus.

According to the announcement, the attackers breached the organizations by leveraging vulnerabilities in targets' or their subcontractors' environments to plant malware capable to exfiltrate data.

The National Police Agency and the Defense Acquisition Program Administration conducted a special inspection earlier this year between January 15 and February 16 and implemented protective measures to secure critical networks.

This special operation discovered multiple companies that had been compromised since late 2022 but were unaware of the breach until authorities informed them.

Diverse attacks

The police report highlights three cases involving each of the mentioned hacking groups, displaying multi-faceted attack methods aimed at stealing defense tech.

Lazarus hackers exploited poorly managed network connection systems designed for testing and penetrated the internal networks of a defense company since November 2022.

After infiltrating the network, they gathered critical data stored in at least six of the firm's computers and transferred it to a cloud server abroad.

Lazarus attack overview
Lazarus attack overview
Korean police

The second attack was attributed to the Andariel group, who stole account information from an employee of a maintenance company that serviced defense subcontractors.

Using this stolen account in October 2022, they installed malware on the servers of these subcontractors, leading to significant leaks of defense-related technical data.

This network infiltration was further exacerbated by employees using the same passwords for personal and work accounts.

Andariel attack overview
Andariel attack overview
Korean police

A third attack highlighted in the police's advisory, Kimsuky exploited a vulnerability in the email server of a defense subcontractor between April and July 2023, which allowed large files to be downloaded without the need to authenticate.

This vulnerability was used to download and steal substantial technical data from the company's internal server.

Kimsuky attack overview
Kimsuky attack overview
​​​​​​​Korean police

The Korean police recommends both defense companies and their subcontractors to improve network security segmentation, periodic password resets, setting up two-factor authentication on all critical accounts, and blocking foreign IP accesses.

Buscar
Categorías
Read More
Cloudflare hacked using auth tokens stolen in Okta attack
February 1, 2024   03:53 PM   4 Cloudflare disclosed today that...
By AFFA 2024-02-02 21:26:35 1 185
Hackers poison source code from largest Discord bot platform
March 25, 2024   02:00 PM   0 The Top.gg Discord bot community...
By AFFA 2024-03-26 14:53:43 0 92
Microsoft will let you manage Linux distros on Windows 11 through GUI
Microsoft added Windows Subsystem for Linux (WSL) to let anyone run a Linux distro directly....
By AFFA 2024-03-25 16:08:05 0 104
Microsoft to shut down 50 cloud services for Russian businesses
March 23, 2024   10:14 AM   0 Microsoft plans to limit access to...
By AFFA 2024-03-23 16:46:43 0 86
Xfinity hack could impact 36 million customers
Hackers compromised a vulnerability in a third-party vendor that serviced Xfinity, which lead to...
By AFFA 2023-12-21 01:11:06 0 276