Hackers tied to North Korea target South Korea through Google Play Store, researchers say
Full article509 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
"We can say it with high confidence that the Lazarus Group is now operating in the mobile world."
Hackers known as the Lazarus Group are targeting Android phones in a new campaign aimed at South Korea, according to researchers at the cybersecurity firm McAfee.
The attack begins with a malware-laced version of a Korean bible study app in the Google Play Store. It’s been downloaded 1,300 times. McAfee attributes the attack to Lazarus Group, which intelligence agencies in the U.S., Britain and elsewhere say is North Korean.
Google Play Store, the app market for the world’s most popular operating system, has a persistent malware issue. On Monday, anti-virus company Avast reported banking malware that avoided Google’s detection and was downloaded thousands of times.
North Korea spends significant resources on building and using cyber-capabilities. One scheme involved stealing $81 million from the central bank of Bangladesh in a heist that ran through the Federal Reserve Bank of New York in 2016. South Korea, North Korea’s chief geopolitical rival alongside the United States, is a frequent target of Lazarus Group hackers.
McAfee researchers said the malware shared multiple characteristics with desktop Lazarus malware discovered in the past, including shared attack infrastructure, code and backdoors.
McAfee attributes the malware to Lazarus Group but does not say Lazarus Group is North Korean.
“And although the debate regarding attribution of attacks will always rage, documenting evolving tactics by threat actor groups allows organizations and consumers to adapt their defenses accordingly,” wrote McAfee analysts Christiaan Beek and Raj Samani.
“We do not know if this is Lazarus’ first activity on a mobile platform,” the researchers said. “But based on the code similarities we can say it with high confidence that the Lazarus Group is now operating in the mobile world.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hackers-tied-north-korea-target-south-korea-google-play-store-researchers-say/