
The Pentagon, FBI and Department of Homeland Security have revealed a new hacking campaign, allegedly carried out hackers by North Korean. Experts have provided technical details on seven different malware samples used in the attacks.
The US Cyber National Mission Force, a part of the Pentagon’s Cyber Command that deals with cybersecurity, said on Twitter that the malware is still being used for phishing attacks and remote access by hackers from the North Korean government. Their goal is to conduct illegal activities, steal funds and evade sanctions.” The tweet linked to a post on VirusTotal. It includes hashes, filenames and other technical details that help experts identify breaches within the networks they protect.
The Department of Homeland Security said the campaign was the work of Hidden Cobra, the US government's name for a hacking group funded by the North Korean government. The group is also known as Lazarus and Zinc.

Here are six of the seven malware uploaded to VirusTotal:
- Bistromath: a trojan that allows remote access and monitors systems, uploads and downloads files, executes processes and commands, monitors microphones, clipboards and screens
- Slickshoes: a “dropper” that has many elements in common with Bistromath
- Hotcroissant: (similar to the above)
- Artfulpie: downloads and executes DLL files from a hardcoded url
- Buttetline: uses a fake HTTPS scheme with a modified RC4 encryption cipher to remain hidden
- Crowdedflounder: a Windows executable file designed to run a remote access Trojan in the computer's memory
However, on Friday, the Cybersecurity and Infrastructure Security Agency provided some additional information about Hoplight , a group of 20 files that act as a proxy-based backdoor. None of the malware contains fake digital signatures, which are commonly used in hacking attacks to bypass security measures .
Costin Raiu, director of Kaspersky Lab, published an image showing the relationship between this malware and others that have been used by the Lazarus group.
The federal government’s public disclosure of this information is a relatively new approach to identifying foreign hackers and their activities. Previously, the government simply linked specific campaigns to specific governments. That began to change in 2014, when the FBI publicly concluded that the North Korean government was behind the hack Sony Pictures. In 2018, the Justice Department said a North Korean agent orchestrated the hack and spread the WannaCry ransomware that disabled millions of computers worldwide in 2017. Last year, the U.S. Treasury Department charged three North Korean hacking groups with attacks on critical infrastructure and stealing millions of dollars from banks and cryptocurrency exchanges.
As Cyberscoop noted , this is the first time that US Cyber Command has publicly acknowledged a hacking campaign from North Korea. This may be due to the fact that hackers from that country are increasingly carrying out attacks and becoming an increasingly bigger threat .
