HomeSecurityDefense industry: The main target of North Korean hackers!

Defense industry: The main target of North Korean hackers!

Since early 2020, the North Korean-backed hacking group “Lazarus” has been targeting the defense industry with custom backdoor malware called ThreatNeedle , with the ultimate goal of stealing sensitive and confidential information. This hacking group has been particularly active in 2020, orchestrating numerous attacks around the world, making it one of the most dangerous cybercrime gangs in the threat landscape today. North Korean hackers have targeted many organizations, and their list of victims has now added the defense industry and companies in more than a dozen countries.

Defense industry: The main target of North Korean hackers!

Attackers have used COVID-19 -themed phishing emails with malicious attachments or links as an initial means of accessing corporate networks. After achieving the initial breach , they would install custom malware “ThreatNeedle,” which was first used in 2018 in attacks targeting cryptocurrency businesses.

Kaspersky security researchers reported that ThreatNeedle, once installed, can gain full control of a victim's device, meaning it can do everything – from manipulating files to executing downloaded commands.

Defense industry: The main target of North Korean hackers!

ThreatNeedle helped North Korean hackers move laterally through defense organizations’ networks and steal sensitive and confidential information, which they then transferred to servers they controlled. In addition, the backdoor allowed hackers to bypass network segmentation and access restricted networks with mission-critical devices that did not have access to the Internet.

According to Kaspersky, the attackers, after "gaining an initial foothold," stole credentials and moved laterally, searching for critical assets in the victims' environment.

Throughout their attacks, North Korean hackers also stole documents and data from devices used to store information about businesses and customers, as well as from restricted networks typically used to store and manage highly sensitive data.

hacking attacks

Lazarus members took control of administrators' workstations, which allowed them to later create malicious portals, which gave them access to restricted networks.

While Lazarus was known for primarily targeting global financial institutions, since the beginning of 2020 when this campaign began, it has shifted its focus and is now focused on the defense industry.

Notably, Google’s Threat Analysis Team reported that the Lazarus hackers have used the same malware to target security researchers. Furthermore, this hacking group is also being monitored under the name “HIDDEN COBRA” by the US Intelligence Community.

Defense industry: The main target of North Korean hackers!

It is a financially motivated cybercrime group, as evidenced by its campaigns, which have targeted Sony Films (as part of the Blockbuster operation in 2014), and were also behind the global WannaCry ransomware campaign of 2017.

Kaspersky recommends that defense industry organizations take the following measures to mitigate the risk of this threat:

  • Staff training on cyber hygiene and awareness of internal security policies
  • Complete segmentation of OT networks from IT networks
  • Notifying security teams about threats
  • Implement dedicated OT network security, including traffic monitoring, analysis and threat detection
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS