Medical and Hospital News
CYBER WARS
U.S. warns of new North Korean email-based cyberattacks
U.S. warns of new North Korean email-based cyberattacks
by Thomas Maresca
Washington DC (UPI) May 3, 2024

North Korean hackers are exploiting an email security flaw in attacks used to gather sensitive intelligence and information, a new U.S. cybersecurity advisory warned.

The advisory, issued Thursday by the FBI, State Department and National Security Agency, said that members of the Pyongyang-backed hacking collective Kimsuky are sending spearphishing emails to individuals at think tanks, academic institutions and media organizations.

Spearphishing is a type of scam that targets specific individuals or groups with personalized information. In this case, the North Korean hackers appear to be legitimate journalists or scholars and are able to hide their identities through improperly configured DNS Domain-based Message Authentication, Reporting and Conformance, or DMARC, records on email systems.

"North Korea leverages these spearphishing campaigns to collect intelligence on geopolitical events, adversary foreign policy strategies, and any information affecting North Korean interests by gaining illicit access to targets' private documents, research and communications," the advisory said.

In one example, a hacker pretending to be a think tank staffer invited a U.S. government official to give a keynote address at a conference on North Korea. In another, a Kimsuky agent posed as a journalist seeking comment on geopolitical issues related to North Korea.

Red flags include awkward sentence structure or grammar and subtle incorrect spellings of legitimate names and email addresses, the advisory said.

Once the hackers establish engagement with a target, they may attempt to follow up with emails containing malicious links and attachments that will compromise the victim's account or network.

Kimsuky is believed to operate under the North's premier military intelligence organization, the Reconnaissance General Bureau. The hacker group is also known as Emerald Sleet, Thallium and Velvet Chollima by private-sector cybersecurity researchers.

"Kimsuky actors' primary mission is to provide stolen data and valuable geopolitical insight to the North Korean regime by compromising policy analysts and other experts," the advisory said. "Successful compromises further enable Kimsuky actors to craft more credible and effective spearphishing emails, which can then be leveraged against more sensitive, higher-value targets."

Washington sanctioned Kimsuky in November, saying its cyber espionage campaigns directly support the North's strategic and nuclear ambitions

North Korea has increasingly turned to hacking and cybertheft in recent years to raise funds for its illicit weapons programs.

Pyongyang funds 40% of its WMD program through "illicit cybermeans," the U.N. Security Council's Panel of Experts estimated in an annual report released in March. The Panel said that 58 suspected cyberattacks on cryptocurrency-related companies generated some $3 billion for the regime between 2017 and 2023.

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
CYBER WARS
Israel builds 'cyber dome' against Iran's hackers
Tel Aviv (AFP) May 3, 2024
Israel's Iron Dome defence system has long shielded it from incoming rockets. Now it is building a "cyber dome" to defend against online attacks, especially from arch foe Iran. "It is a silent war, one which is not visible," said Aviram Atzaba, the Israeli National Cyber Directorate's head of international cooperation. While Israel has fought Hamas in Gaza since the October 7 attack, it has also faced a significant increase in cyberattacks from Iran and its allies, Atzaba said. "They are tr ... read more

CYBER WARS
High winds temporarily halt Gaza pier construction

In southern Brazil, flood victims cope with total loss

'Slightly' more food available in Gaza but famine still looms: WHO

Death toll from south China road collapse rises to 48

CYBER WARS
Galileo satellite constellation expands with two new additions

Finnair suspends flights to Estonian city over Russian GPS interference

Exploring the marvels of Galileo: Europe's satellite navigation system

TrustPoint Secures AFWERX Phase II Contract for Advanced Navigation Solutions

CYBER WARS
UK researchers unveil face of 75,000-year-old Neanderthal woman

A world with fewer children? Addressing the despair behind declining fertility

LGBTQ Iraqis fear dark days ahead after anti-gay law

Ancient landscapes point to Australia's initial human migration paths

CYBER WARS
'Bloodsicles', baths keep Philippine zoo animals cool as heatwave hits

NASA Is Helping Protect Tigers, Jaguars, and Elephants

Research: Rising temperatures threatening bumblebee populations

US Republicans vote to remove wolf protections

CYBER WARS
Latin America, Caribbean set for record dengue season

US conspiracy theorists monetize 'Disease X' misinformation

CYBER WARS
Xi, Macron to discuss Ukraine during China leader's visit

Australia's former top diplomat to sue N. Zealand FM over China barb

Japan monitoring reports of professor 'missing' in China

Canada FM sending deputy to China to work on tense ties: source

CYBER WARS
Colombian rebels holding Amazon hostage in peace talks

Hong Kong customs makes largest-ever gold smuggling bust

Indian navy says intercepted hijacked vessel near Somalia

Bodies of eight Chinese migrants found on beach in Mexico

CYBER WARS
Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.