HomeSecurityHackers forge emails from trusted sources

Hackers are forging emails from trusted sources

On Thursday, the US government issued a cybersecurity advisory, warning of attacks by North Korean hackers who are attempting to send phishing emails, crafted to appear to come from legitimate and trusted sources.

hackers emails

See also: Moldovan government hit by NoName Ransomware

“The Democratic People’s Republic of Korea (DPRK) exploits phishing campaigns to illegally gain access to and collect important information concerning geopolitical events, foreign policy strategies of adversaries, as well as any data that may affect the DPRK’s national interests, through illegal access to private documents, research, and communications,” the NSA said.

This technique refers to the use of DNS domain-based authentication, reporting, and message harmonization registration policies that are not properly configured to hide social engineering attempts. hackers can send fake emails that appear to come from a legitimate email server.

Inadequate use of weak DMARC policies has been linked to North Korean actions, which the cybersecurity under the name Kimsuky (also known as APT43, Black Banshee, Emerald Sleet, Springtail, TA427, and Velvet Chollima). This group, affiliated with the Lazarus Group and the Reconnaissance General Bureau (RGB), poses a critical cybersecurity threat.

A recent report by Proofpoint said Kimsuky began implementing a new tactic in December 2023, part of a broader strategy to target foreign policy experts. The goal was to obtain information and opinions on nuclear disarmament issues, US-South Korea relations, and sanctions.

Calling the adversary a “social engineering expert,” the firm described the hacking group as experts at engaging with their targets for long periods, conducting carefully crafted conversations to gain the trust of victims. Using a variety of aliases, the group presents itself as experts in think tanks, academia, journalism, and independent research, targeting the DPRK.

"Targets are often asked to share their opinions on specific topics, either via email or through a formal research paper or article," said Proofpoint researchers Greg Lesnewich and Crista Giering.

“Malware or credential extraction is never directly embedded in targets without a series of message exchanges, and is rarely the threat actor’s choice. It seems likely that TA427 is able to satisfy its information by directly soliciting targets for their opinions or analysis, without the need for infection.”

The company also pointed out that many of the organizations targeted by TA427 had not enabled or implemented DMARC policies, thus allowing forged emails to bypass security measures and reach their destination even if these checks failed.

Additionally, it has been observed that the Kimsuky uses email addresses, formatting them so that they appear in the reply field to come from legitimate individuals, in order to convince the recipient of their authenticity and gain their trust.

In an email flagged by the US government, the threat actor posed as a legitimate journalist, expressing interest in an interview with an anonymous expert on North Korea’s nuclear plans. He then stated that the email account would be temporarily blocked, prompting the recipient to respond to a personal email – which turned out to be a fake account impersonating the journalist.

hackers emails

Read more: Junk gun Ransomware: New cheap threat to small businesses

This means that the phishing message was initially sent from the journalist's compromised account, thus setting the stage for increased chances that the victim will trust and respond to the fake emails.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is recommended that organizations upgrade their DMARC policies to instruct email servers to treat emails that fail security checks as suspicious or spam, deciding whether to quarantine or drop them. Additionally, by setting up an email address in the DMARC record, they can receive aggregated feedback reports, thereby improving the security and management of their emails.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS