ZeroHour
Schneier on Securitypublished ()ingested

Nation-State Espionage Campaigns against Middle East Defense Contractors

highThreat actorimportance 57
Full article124 words · extracted from schneier.com · click to collapse

Report on espionage attacks using LinkedIn as a vector for malware, with details and screenshots. They talk about “several hints suggesting a possible link” to the Lazarus group (aka North Korea), but that’s by no means definite.

As part of the initial compromise phase, the Operation In(ter)ception attackers had created fake LinkedIn accounts posing as HR representatives of well-known companies in the aerospace and defense industries. In our investigation, we’ve seen profiles impersonating Collins Aerospace (formerly Rockwell Collins) and General Dynamics, both major US corporations in the field.

Detailed report.

Tags: attribution, cyberespionage, espionage, impersonation, LinkedIn, malware, reports

Posted on June 23, 2020 at 6:22 AM12 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2020/06/nation-state_es.html