A server likely used by Lazarus Group offers clues to a broader espionage campaign
Full article608 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
An analysis of a suspected Lazarus C2 server hows it was the centerpiece of a espionage campaign that is broader and longer-running than previously understood.
An analysis of a command-and-control server suspected of being used by North Korean hackers shows it was the centerpiece of a previously discovered global espionage campaign that is broader and longer-running than initially understood, security researchers with McAfee announced Sunday.
The campaign began as early as September 2017, a year earlier than previously documented, and is targeting financial services and government organizations, among others, researchers said. Most of the malicious activity is against organizations in Germany, Turkey, the U.S., and the United Kingdom, the researchers said.
In December, McAfee published research on the espionage campaign, dubbed Operation Sharpshooter, saying it hit 87 organizations – including those in the nuclear, defense, and financial sectors – in October and November alone.
After picking apart code and other data from the server, McAfee researchers say they’ve found “striking similarities” between last year’s attacks and several others attributed to Lazarus Group, a broad set of suspected North Korean hackers. They also describe a “factory-like process” used by Lazarus where components of a malicious implant have been developed independently and employed in various settings since 2016.
The hackers appear to have tested their malicious implants using far-flung infrastructure. Researchers found a set of IP addresses accessing the server that originated from the African nation of Namibia. “We saw the actor was using the infrastructure to test small runs of sending out the implants, not as the larger bursts we observed during” the espionage campaign, Christiaan Beek, McAfee’s lead scientist, told CyberScoop.
An unnamed government organization gave McAfee access to the server likely used by Lazarus, which U.S. officials have blamed for the destructive attack on Sony Pictures in 2014 and for the WannaCry ransomware outbreak in 2017.
While North Korean hackers are well-known for those highly-visible hacks, they have also been linked to espionage activities – both for economic gain and traditional intelligence collection. For example, they have allegedly used a Google Chrome extension to spy on academics. As North Korea feels the bite of international sanctions, some analysts expect the government’s hackers to ramp up commercial espionage this year.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/lazarus-group-mcafee-operation-sharpshooter/