HomeSecurityKimsuky hackers impersonate journalists to steal information

Kimsuky hackers impersonate journalists to steal information

Security researchers have warned that the Kimsusy hackers backed by the North Korean government impersonate journalists in order to gather strategic information that will aid the country's decision‑making.

Kimsuky

SentinelLabs researchers said Tuesday they have linked a social engineering campaign targeting North Korea experts to a North Korean APT group known as Kimsuky. The group, also known as APT43, Thallium and Black Banshee, has been active since at least 2012 and is known for using social engineering and targeted phishing to gather sensitive information on behalf of the North Korean.

The latest social engineering campaign by the Kimsuky group targeted the subscribers of NK News, an American subscription website that provides news and analysis regarding North Korea.

See also: Traditional malware exploits interest in ChatGPT

Sentinel Labs observed that the threat actor Kimsuky impersonated Chad O’Carroll, the founder of NK News, in order to deliver a forged Google Docs link to NK News subscribers. This link redirects to a malicious website, which was specifically crafted to steal the victims' Google credentials. In some cases, Kimsuky hackers also delivered a weaponized Microsoft Office document that runs the ReconShark malware, which is capable of hiding information such as detection mechanisms used on a device and information about the device itself.

In another attack observed by SentinelLabs, the threat actor Kimsuky sent an email message that asked subscribers to log in to a spoofed NK News subscription service. Gaining access to the credentials of NK News users would provide North Korean hackers “valuable information on how the international community assesses and interprets developments related to North Korea”, contributing to their broader initiatives for gathering strategic intelligence, as wrote Aleksandar Milenkoski, senior threat researcher at SentinelLabs.

Kimsuky hackers impersonate journalists to steal information

Kimsuky was also observed sending legitimate Google Docs links and Word documents that did not contain malicious software, in order to develop a relationship with its targets before it began its malicious activities.

Sentinel Labs' analysis comes just days after the US and South Korean governments issued an advisory warning that Kimsuky was conducting targeted spear-phishing to funnel valuable geopolitical information and other stolen data to the North Korean regime.

See also: Pharmaceutical company Eisai hit by ransomware attack

The public advisory warned that the Kimsuky group impersonates journalists, academics, think‑tank researchers and government officials to target individuals dealing with North Korean affairs.

Information source: techcrunch.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS