Amid the COVID-19, North Korean hackers have targeted the U.S. defense and aerospace sectors, using fake job offers as bait to infect employees seeking better career prospects and gain access to their organizations’ networks. The attacks began in late March and continued through May 2020, according to cybersecurity firm McAfee. McAfee said the attacks , codenamed “Operation North Star,” have been linked to infrastructure and TTPs (Techniques, Tactics, and Procedures) previously associated with Hidden Cobra – a term the U.S. government uses to describe organized hacking groups funded by North Korea.

The company also noted that the attacks used spear-phishing to lure recipients into opening documents purporting to contain a job offer. Many hacking groups have used job offers as bait in the past, with North Korean hackers using it in attacks on the U.S. defense sector in 2017 and 2019, said Christiaan Beek, chief scientist and senior principal engineer.

The 2017 attacks involved US charges against a North Korean hacker believed to have been involved in the attacks, as well as in the creation of the WannaCry ransomware. The 2020 attacks also used malware, while reaching some victims not only through email but also through social media.
The entire attack chain – from contact to the way the malware operates, is described in detail in the chart below with full technical details from McAfee.

However, the effectiveness of this campaign is not yet known. Given that the pandemic has affected workers, it is unclear how much success North Korean hackers had using a topic that involved a “new job”, to lure victims. McAfee reported that it could not accurately determine which US defense or aerospace companies were the targets of these attacks, to notify them. The only things it could determine were the nature of the fake job positions (Senior Design Engineer and System Engineer) and the US defense sectors that the hackers targeted:
- F-22 Fighter Jet Program
- Defense, Space and Security (DSS)
- Photovoltaics for space solar cells
- Aeronautics Integrated Fighter Group
- Military Aircraft Modernization Programs
Raj Samani, McAfee's chief scientist, told ZDNet that the company has reached out to US cybersecurity to inform authorities about the attacks.
The North Star campaign is aimed at espionage and gathering information that could be used to benefit North Korea.

As the country is under heavy economic sanctions and without a self‑sustaining military‑industrial complex, it can only support the program and its ambitions for nuclear weapons, importing or stealing the information it needs – which, in this case, it hopes to obtain from the US defense and aerospace sectors.
However, another way North Korea maintains its nuclear program is by allowing hackers to engage in cybercrime. Meanwhile, security firm Kaspersky published a report this week linking North Korean hackers to a new ransomware strain called VHD.
Before this, the group was also linked to other types of cybercrime, such as BEC scams, Magecart attacks, bank robberies, cryptocurrency breaches and scams, and botnets . Finally, North Korea has built one of the most powerful and advanced hacking armies to date, as evidenced by the variety of its operations.
