New hacking campaign targets North Korean defectors in South Korea
Full article606 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
"The actors are familiar with South Korea and appear to want to spy on North Korean defectors, and on groups and individuals who help defectors," according to a researcher.
A group of hackers is targeting defectors and journalists in South Korea with malware sent via popular chat apps and social networks, according to the cybersecurity firm McAfee.
The “highly targeted” campaign beginning in 2017 used Facebook and KakaoTalk, one of South Korea’s most popular chat apps, to spread malware-laced phishing links to targets. The attacks show that “attackers are always looking for different ways to deliver malware,” McAfee’s Jaewon Min wrote. This particular group does not appear to have links to any existing cybercrime groups, the post says.
Although McAfee offered no definitive answers on who is behind the campaign, the firm’s report did show links to North Korea in the form of an IP address in test log files on some Android devices connected to accounts used to spread the malware. Additionally, some words used in the code are almost exclusively used in North Korea, and the targets are all of great interest to the North.
North Korea has spent the last decade jumpstarting its cyber capabilities. As its closest and most important rival, South Korea is a frequent target. Likewise, the North appears to be a regular target of cyber campaigns by South Korea and its allies. In just the last few months, North Korea stands accused of a rash of profit-driven hacking campaigns around the world.
The malware is hidden in two droppers, or installers, titled “북한기도” (Pray for North Korea) and “BloodAssistant” (a health care app), according to McAfee. Journalists were targeted with fake news stories directing to infected websites.

Malware droppers. (McAfee)
McAfee researchers found a deleted folder with the title “sun Team Folder,” a possible hint at the name of the threat actors.
“This malware campaign is highly targeted, using social network services and KakaoTalk to directly approach targets and implant spyware,” McAfee’s Jaewon Min wrote in a report on the campaign.
“We cannot confirm who is behind this campaign, and the possible actor Sun Team is not related to any previously known cybercrime groups. The actors are familiar with South Korea and appear to want to spy on North Korean defectors, and on groups and individuals who help defectors.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/new-hacking-campaign-targets-north-korean-defectors-in-south-korea/