HomeSecurityNorth Korean Hackers Target Brazil

North Korean hackers target Brazil

North Korean hackers account for a third of phishing attacks targeting Brazil since 2020.

hackers North Korea Brazil

“Cyberattacks supported by the North Korean government have targeted the Brazilian government as well as the country’s aerospace, technology, and financial services sectors,” Google’s Mandiant and Threat Analysis Group (TAG) said in a report published this week.

Read more: North Korean hackers are incorporating AI into their attacks

"Among their interests, cryptocurrency and fintech companies are at the forefront, with at least three North Korean gangs having attacked Brazilian companies in the sector.".

The UNC4899 threat actor (also known as Jade Sleet, PUKCHONG, and TraderTraitor) holds a special place among these threat groups. It has targeted cryptocurrency professionals via a Python loaded with malware. The attacks involve approaching potential targets via social media and sending a seemingly innocent PDF containing a job posting at a well-known cryptocurrency company.

If the target expresses interest, the hacker follows up by sending a second, secure PDF. This includes a skills questionnaire and instructions for completing a coding assignment by downloading a project from GitHub.

“The project was a modified (trojanized) Python application, pretending to retrieve cryptocurrency prices, that was customized to connect to a domain controlled by the hackers to retrieve a second malicious payload when certain conditions were met,” as reported by Mandiant and TAG researchers.

Read more: US: Five people charged with raising revenue for North Korea's nuclear program

This isn’t the first time UNC4899 – who was also involved in the 2023 JumpCloud attack – has used this approach. In July 2023, GitHub warned of a social engineering that aimed to trick employees of blockchain, cryptocurrency, online gaming, and cybersecurity companies into executing code from a GitHub repository using fake npm packages.

Social engineering campaigns with a work theme are a recurring pattern among North Korean hacking groups. The tech giant recently detected a campaign by the PAEKTUSAN group that delivered C++ malware called AGAMEMNON via Microsoft Word in phishing emails.

In one example, PAEKTUSAN created a fake HR manager account at a Brazilian aerospace company and used it to send phishing emails to employees at another Brazilian aerospace company. Researchers note that these campaigns align with the long-running activity known as Operation Dream Job.

In another campaign, PAEKTUSAN disguised itself as a military officer for a major American aerospace company, reaching out to professionals in Brazil and other regions via email and social media about fake job opportunities.

See more: FBI: New crypto scam via fake job ads

Google also said it blocked efforts by another North Korean group called PRONTO to target diplomats, using bait to lure them to credential collection pages or convince them to provide their login details to view a fake PDF document .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

These developments come just weeks after Microsoft revealed a previously undocumented North Korean threat actor, codenamed Moonstone Sleet, that targets individuals and organizations in the software, information technology, education, and defense industries through ransomware and cyberespionage.

Moonstone Sleet's tactics include distributing malware via fake npm packages published to the npm registry, similar to UNC4899's practices. These packages vary in style and code structure.

“The Jade Sleet packages, discovered in the summer of 2023, were designed to operate in pairs, with each pair published by a separate npm user account to distribute their malicious activity,” said Checkmarx researchers Tzachi Zornstein and Yehuda Gelb. In contrast, the packages published in late 2023 and early 2024 took a more streamlined approach, executing their payload immediately upon installation. In the second quarter of 2024, these packages became more sophisticated, with attackers adding obfuscation and targeting Linux.

Despite the differences, this strategy abuses users' trust in open source repositories, allowing threat actors to reach a wider audience, increasing the likelihood of malicious packages being installed by unsuspecting developers.

See also: North Korean workers infiltrate freelance IT networks to steal data

This revelation is significant, as it marks the expansion of the Moonstone Sleet malware distribution mechanism, which previously relied on spreading fake npm packages via LinkedIn and freelancer websites.

hackers North Korea Brazil

The findings also tie in with the discovery of a new social engineering campaign by North Korea's Kimsuky group, which impersonated the Reuters news agency to target North Korean human rights activists, distributing information-stealing malware under the guise of an interview request, according to Genians.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS