{"id":2744,"date":"2024-03-18T19:00:00","date_gmt":"2024-03-19T00:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/north-korea-linked-group-level-multistage-cyberattack-on-south-korea"},"modified":"2024-03-18T19:00:00","modified_gmt":"2024-03-19T00:00:00","slug":"north-korea-linked-group-levels-multistage-cyberattack-on-south-korea","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/18\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea\/","title":{"rendered":"North Korea-Linked Group Levels Multistage Cyberattack on South Korea"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt6f092f0df0aaff58\/64f174bc705b0eaf4d4ca749\/northkorea_David_Carillet_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">North Korea-linked threat group Kimsuky has adopted a longer, eight-stage attack chain that abuses legitimate cloud services and employs evasive malware to conduct cyber espionage and financial crimes against South Korean entities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a campaign dubbed &#8220;DEEP#GOSU,&#8221; which is attributed to the group, the cyber-espionage operators were very much focused on a strategy of &#8220;living off the land,&#8221; using commands to install a variety of .NET assemblies&nbsp;\u2014 legitimate code components for .NET applications \u2014 to create the foundation of the attacker&#8217;s toolkit, researchers from Securonix wrote in a threat analysis today.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kimsuky also used LNK files attached to emails, command scripts downloads from Dropbox, and code written in PowerShell and VBScript to conduct offensive operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While typical cyberattacks use five or fewer stages, the DEEP#GOSU campaign used eight. And though some of the tools could be detected by antivirus scanners and other defensive technologies, the attackers actively aimed to foil detection, says Oleg Kolesnikov, vice president of threat research at Securonix.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There were many different components and payloads, and different payload components had different scanner detection rates,&#8221; he says. &#8220;Since the attackers actively used evasion and disruption of security tool techniques \u2014 including shutting down security tools and adding payloads to exclusions, among others \u2014 the number of scanners detecting this was likely less relevant in this case.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Kimsuky group \u2014 also known as APT43, Emerald Sleet, and Velvet Chollima \u2014 ramped up <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/north-korea-kimsuky-apt-keeps-growing-despite-public-outing\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">its activity in 2023<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, shifting to a greater focus on cryptocurrency in addition to its traditional focus on cyber espionage. Kimsuky is well known for its skilled spear-phishing, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/north-korea-kimsuky-evolves-full-fledged-persistent-threat\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">not necessarily for its technical sophistication<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but the latest attack demonstrated that the group has evolved somewhat, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.securonix.com\/blog\/securonix-threat-research-security-advisory-new-deepgosu-attack-campaign\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the analysis penned by three researchers at Securonix<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The malware payloads &#8230; represent a sophisticated, multi-stage threat designed to operate stealthily on Windows systems especially from a network-monitoring standpoint,&#8221; the trio of researchers stated in their analysis. &#8220;Each stage was encrypted using AES and a common password and IV [initialization vector] which should minimize network, or flat file scanning detections.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Using Dropbox and Google to Evade Security Controls\">Using Dropbox and Google to Evade Security Controls<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first stage of the attack executes when the user opens a LNK file attached to an email, which downloads PowerShell code from Dropbox. The code executed during the second stage downloads additional scripts from Dropbox and prompts the compromised system to install a remote access Trojan, the TutClient, at Stage 3.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The heavy use of Dropbox, and Google in later stages, helps avoid detection, Securonix&#8217;s threat researchers stated in the analysis.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;All of the C2 communication is handled through legitimate services such as Dropbox or Google Docs allowing the malware to blend undetected into regular network traffic,&#8221; they wrote. &#8220;Since these payloads were pulled from remote sources like Dropbox, it allowed the malware maintainers to dynamically update its functionalities or deploy additional modules without direct interaction with the system.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The later stages of the attack install a script that randomly executes in a matter of hours to help monitor and control systems and provide persistence. The final stage monitors user activity through logging keystrokes on the compromised system.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multistage Attacks Highlight Defense in Depth\">Multistage Attacks Highlight Defense in Depth<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While detection rates for the initial stages of the attack ranged from 5% to 45% for host-based security, network security platforms may have a hard time detecting the later stages of the attacks because the Kimsuky threat actors use encrypted traffic, legitimate cloud file-transfer services, and downloaded .NET components.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The multipronged attack highlights the benefits of having multiple layers of defenses, Kolesnikov says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In our experience, in cases such as this, up-to-date antivirus may not be enough because the behaviors exhibited include disrupting and evading security tools,&#8221; Kolesnikov says. &#8220;Our recommendation is for organizations to leverage defense-in-depth so as not to rely on any specific security tool alone.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Email security gateways, for example, would likely block the LNK file because of its massive 2.2MB size, compared with typical sizes measured in kilobytes, he says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/north-korea-linked-group-level-multistage-cyberattack-on-south-korea\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korea-linked threat group Kimsuky has adopted a longer, eight-stage<\/p>\n","protected":false},"author":12,"featured_media":2745,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2744","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=1000%2C650&ssl=1",1000,650,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=300%2C195&ssl=1",300,195,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=640%2C416&ssl=1",640,416,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=640%2C416&ssl=1",640,416,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=1000%2C650&ssl=1",1000,650,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=1000%2C650&ssl=1",1000,650,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=1000%2C650&ssl=1",1000,650,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/north-korea-linked-group-levels-multistage-cyberattack-on-south-korea.jpg?fit=1000%2C650&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2744"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2744\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2745"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}