U.S. government issues new warning about North Korea
Full article606 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The mitigations DHS recommends have added urgency because of the way the North Korean hackers are seizing on weak security practices.
Department of Homeland Security and FBI officials are warning industry about what they say are new Trojan malware variants that North Korean-government-backed hackers have deployed as part of their global operations.
The variants employ proxy applications to mask communications between the malicious programs and their operators, DHS said in a report published Wednesday. When executed, the malware collects information on the victim machine’s operating system and its system time, and uses a public SSL certificate for secure communication with its operators, the report said. DHS has dubbed the new malware HOPLIGHT.
“This is continuing our campaign to put pressure on the DPRK as well as helping network defenders understand some of the tools and the capabilities that they are using,” Jeanette Manfra, assistant director for cybersecurity at DHS’s Cybersecurity and Infrastructure Security Agency, told CyberScoop.
The mitigations that DHS recommends – such as updating antivirus signatures and disabling file-sharing services – aren’t radical but they have added urgency because of the way the North Korean hackers are seizing on weak security practices, according to Manfra.
“The North Koreans are exploiting the fact that people aren’t doing some of these things to get access to infrastructure, to further their operations,” she said.
One of the goals of publishing the report was to “reduce the ability of the actors to continue to use this malware,” Manfra added – something she dubbed “deterrence by denial.” The department has released no less than 15 reports and advisories on suspected North Korean cyber operatives, according to Manfra.
For U.S. officials, deterring North Korean hackers, who have shown few scruples in what they target, is a work in progress. The FBI quietly told U.S. companies last October that North Korean hackers will continue to target financial institutions worldwide despite the U.S. government’s public attribution of such activity to Pyongyang.
Jon DiMaggio, a senior threat intelligence analyst at Symantec, said that, based on the U.S. government’s attribution, the new variants reinforce the notion that North Korea-linked hackers are “very quick to evolve on their malware, and they’re very quick to tailor it to fit their operations from one campaign to the next.”
Symantec plans to analyze the new variants and strengthen its antivirus signatures to further protect against the malicious activity reported by DHS, DiMaggio added.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/north-korea-malware-lazarus-group-dhs/