Hacking campaign on nuclear, defense sectors shares Lazarus Group tools, report says
Full article567 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
“Operation Sharpshooter” has numerous technical links to the group of suspected North Korean government hackers blamed for the 2014 breach at Sony Pictures and other well-publicized attacks, according to McAfee researchers.
Hackers behind a new campaign of cyberattacks that have targeted international critical infrastructure facilities are using malicious code linked to North Korea, according to research published Wednesday.
Researchers from McAfee said “Operation Sharpshooter” has numerous technical links to the Lazarus Group, the group of suspected North Korean government hackers blamed for the 2014 breach at Sony Pictures and other well-publicized attacks.
Operation Sharpshooter used a hacking tool called “Rising Sun” to target 87 organizations, mostly in the U.S., between October and November of this year, McAfee said. The cybersecurity vendor did not flatly tie this campaign to the North Korean government.
“Attributing an attack to any threat group is often riddled with challenges, including potential ‘false flag’ operations by other threat actors,” the research states. “Technical evidence alone is not sufficient to attribute this activity with high confidence. However, based on our analysis, this operation shares multiple striking similarities with other Lazarus Group attacks[.]”
The Rising Sun tool is an evolution of a Lazarus-made tool called Duuzer, which circulated in 2015 and was used against South Korea, McAfee said. The email campaign began Oct. 25 with a series of messages that appeared to be from a sender named Richard. Hackers sent English-language emails that appeared to contain job description for positions at unknown companies, though the messages in fact the contained malware that would infect a recipient’s machine.
Firms operating in the nuclear, defense, energy and financial sectors were targeted.
“We have not previously observed this implant,” McAfee said. “Based on our telemetry, we discovered that multiple victims … have reported these indicators.”
The operation comes at roughly the same time researchers have blamed the Lazarus Group for a number of other incidents. The North Korean hackers have been especially focused on cryptocurrency exchanges to help the government subvert sanctions, CyberScoop reported last month. Such attacks “will continue unabated, regardless of the U.S. government public attribution of North Korea,” the FBI said in an October advisory obtained by CyberScoop.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/lazarus-group-north-korea-nuclear-defense-mcafee/