{"id":3385,"date":"2024-05-02T15:45:23","date_gmt":"2024-05-02T20:45:23","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn"},"modified":"2024-05-02T15:45:23","modified_gmt":"2024-05-02T20:45:23","slug":"dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/02\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn\/","title":{"rendered":"DPRK&#8217;s Kimsuky APT Abuses Weak DMARC Policies, Feds Warn"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt1fc1c2083098d288\/64f152383f0a22ee009e15c3\/dprk_panther_media_GmbH_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">North Korean hackers are taking advantage of weak DMARC configurations to impersonate organizations in phishing attacks against individuals of strategic significance to the Kim Jong Un regime.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DMARC, short for Domain-based Message Authentication, Reporting &amp; Conformance, is a security protocol for preventing email-based attacks. Unlike most security solutions, however, which potential victims implement for themselves, DMARC policies are set by email senders. In part for this reason, it can be easily overlooked.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On Thursday, the FBI and National Security Agency released a joint cybersecurity advisory detailing how the APT <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/north-korea-kimsuky-apt-keeps-growing-despite-public-outing\" rel=\"noopener\">Kimsuky<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (aka APT 43, Thallium) is taking advantage. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/twitter.com\/aptwhatnow\/status\/1737216467160977496\" rel=\"noopener\">For some time now<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it has been masquerading as organizations that have weak or nonexistent DMARC policies in convincing spear phishing emails.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is a highly effective new tool in the arsenal of one of the more prolific social engineering threat groups that Mandiant tracks,&#8221; Gary Freas, Mandiant senior analyst with Google Cloud, said in an email. &#8220;Organizations in a variety of industries around the world are at risk of leaving themselves unnecessarily exposed. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/tech-tip-why-haven-t-you-set-up-dmarc-yet-\" rel=\"noopener\">Proper DMARC configuration<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, in conjunction with proper management of SPF\/DKIM, is low-hanging fruit to deliver high-impact prevention of phishing and spoofing of an organization.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Difference DMARC Makes\">The Difference DMARC Makes<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kimsuky&#8217;s primary objective is to steal valuable intelligence \u2014 regarding geopolitical events, other nations&#8217; foreign policy strategies, and more \u2014 for the Kim regime. To do that, it aims cyberattacks at journalists, think tanks, government organizations, and the like.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To add legitimacy to these attacks, it often impersonates individuals from trusted organizations like these in highly targeted emails. Such emails are extra convincing when Kimsuky gains access to their puppet&#8217;s legitimate account or domain (often through a separate spear phishing attack) to send emails on their behalf.<\/span><\/p>\n<div readability=\"7\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_center\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"A Kimsuky phishing email sent from late 2023 to early 2024. Source: FBI\/NSA\" title=\"A Kimsuky phishing email sent from late 2023 to early 2024. Source: FBI\/NSA\"><\/p>\n<p class=\"ContentImage-Link\">A Kimsuky phishing email sent from late 2023 to early 2024. Source: FBI\/NSA<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is what DMARC is designed to prevent. It combines two authentication mechanisms: the Sender Policy Framework (SPF), which checks that a sender&#8217;s IP address is authorized to send emails from their specified domain, and DomainKeys Identified Mail (DKIM), which uses public key cryptography for anti-tampering. Domain owners can set a DMARC record in their domain name system (DNS) settings to determine what happens should an email-en-route fail one of these checks: either block it (p=reject), treat it with suspicion (p=quarantine), or do nothing (p=none).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The FBI-NSA joint advisory suggests organizations favor p=reject or p=quarantine to prevent threat actors like Kimsuky from sending emails from their domains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;DMARC hygiene is critical,&#8221; says Jeremy Fuchs, Harmony Email analyst at Check Point. &#8220;It&#8217;s a fantastic way to ensure that when someone gets an email from your company, it\u2019s actually from your company. It can be a big project, though, to ensure p=reject state, especially when you have many domains. This is why reporting, monitoring, and consistent hygiene is key.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;DMARC is not a silver bullet, as hackers have plenty of ways to spoof, but it can be a good starting point.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean hackers are taking advantage of weak DMARC configurations<\/p>\n","protected":false},"author":12,"featured_media":3386,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3385","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=2560%2C1629&ssl=1",2560,1629,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=300%2C191&ssl=1",300,191,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=640%2C408&ssl=1",640,408,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=640%2C408&ssl=1",640,408,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=1536%2C977&ssl=1",1536,977,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=2048%2C1303&ssl=1",2048,1303,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=1024%2C652&ssl=1",1024,652,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn-scaled.jpg?fit=2560%2C1629&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3385"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3385\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3386"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}