{"id":5140,"date":"2024-09-04T11:57:40","date_gmt":"2024-09-04T16:57:40","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-north-korean-actors-aggressive-cyberattack-wave"},"modified":"2024-09-04T11:57:40","modified_gmt":"2024-09-04T16:57:40","slug":"fbi-north-korean-actors-readying-aggressive-cyberattack-wave","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/04\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave\/","title":{"rendered":"FBI: North Korean Actors Readying Aggressive Cyberattack Wave"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8b3d507806adcb9a\/66d840e9d85c63da2a50eff6\/northkorea_DD_Images_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">North Korean threat actors are expected to launch imminent attacks aimed at stealing funds from &#8220;organizations with access to large quantities of cryptocurrency-related assets or products,&#8221; the FBI is warning, adding that the attacks will use particularly deceptive social engineering tactics, including highly personalized targeting that will appear extremely convincing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the last several months, federal officials have observed various state-sponsored actors from the DPKR conducting research on targets connected to crypto exchange-traded funds (ETFs). The reconnaissance appears to be pre-operational in nature, the agency said in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ic3.gov\/Media\/Y2024\/PSA240903\" rel=\"noopener\">a public service announcement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published yesterday.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Impending attacks \u2014 which may include both crypto theft and the deployment of malware \u2014 &nbsp;likely will come in stealth form, including as what may appear as innocuous conversations with people who speak English fluently and appear to have an authentic business reasons for contact, or job opportunities for employees. Attackers also will likely play the long game, taking the time to cultivate a personal relationship before doing anything malicious, the agency said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, North Korean advanced persistent threats (APTs) such as Lazarus and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn\" rel=\"noopener\">Kimsuky<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> are particularly adept at using social engineering to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/north-korean-attackers-targeted-crypto-companies-in-jumpcloud-breach\" rel=\"noopener\">steal crypto<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in threat campaigns aimed to gather funds to support the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/un-digging-into-dprk-crypto-cyberattacks-totaling-3b\" rel=\"noopener\">country&#8217;s nuclear program<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as well as other endeavors of North Korea&#8217;s Supreme Leader Kim Jong Un. In fact, the United Nations estimates that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/north-korean-apt-exploits-novel-chromium-windows-bugs-steal-crypto\" rel=\"noopener\">North Korean attackers have stolen<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> up to $3 billion in crypto so far in such targeted attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In these campaigns, state-sponsored actors convincingly impersonate recruiters and headhunters to target employees of different sectors, and even apply for and sometimes <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/security-firm-hires-north-korean-hacker-knowbe4\" rel=\"noopener\">get hired for jobs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in US firms to engage in malicious activity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This fresh wave of attacks may be even more difficult to detect than previous ones, requiring vigilance on the part of the employees of crypto firms to monitor for any even remotely suspicious activity, the FBI said. &#8220;Given the scale and persistence of this malicious activity, even those well-versed in cybersecurity practices can be vulnerable to North Korea&#8217;s determination to compromise networks connected to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/feds-seize-sinbad-crypto-mixer-used-by-north-korea-s-lazarus\" rel=\"noopener\">cryptocurrency assets<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; according to the warning.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Social Engineering to Watch Out For\">Social Engineering to Watch Out For<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers likely will use variations on three key areas of social engineering even before attackers even attempt to engage in technologically malicious activity, according to the FBI. The idea is to win the trust of employees of crypto firms so they can gain access to accounts, systems, or other assets of their respective companies in a way that does not raise suspicion.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, they may engage in extensive research to identify <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/defi-pummeled-by-cybercriminals\" rel=\"noopener\">specific DeFi <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">or cryptocurrency-related businesses to target, and doing their homework on employees by reviewing their social media activity, particularly as it appears on professional networking or employment-related firms, the agency said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Armed with this info, attackers will move to the next phase of the ruse, with individualized fake scenarios that leverage &#8220;personal details regarding an intended victim\u2019s background, skills, employment, or business interests to craft customized fictional scenarios designed to be uniquely appealing to the targeted person,&#8221; according to the warning.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These can include offers of new employment or corporate investment that draw on employees&#8217; personal details and thus appeal to their interests or emotions, thus setting up a trust relationship that&#8217;s furthered by prolonged conversations aimed at building a friendly rapport.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A third tactic used by attackers is to impersonate people that a victim may know personally or indirectly, such as a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/fake-recruiters-defraud-facebook-users-remote-work-offers\" rel=\"noopener\">recruiter on a professional networking website<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> or a prominent person in a related technology field. These impersonations may be accompanied by the use of photos stolen from social media profiles or professional websites.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Final Phase: Malicious Cyber Activity\">Final Phase: Malicious Cyber Activity<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once the social relationship between the North Korean attacker and victim is solidified, threat actors will then proceed to make requests or offers that eventually lead to the deployment of malware or the theft of cryptocurrency.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These include requests to execute code or download applications on devices with access to a company&#8217;s internal network, or to conduct a pre-employment test or debugging exercise that involves executing non-standard or unknown Node.js packages, PyPI packages, scripts, or <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/millions-of-malicious-repositories-flood-github\" rel=\"noopener\">GitHub repositories<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers also may insist on using non-standard or custom software to complete simple tasks easily achievable through the use of common applications, such as video conferencing, as a way to smuggle malware onto an organization&#8217;s network. They also may request to move professional conversations to other messaging platforms or applications for a similar goal, or send links or attachments that conceal malware to targeted employees related to the previously established communication.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mitigation Against DPRK Crypto Theft\">Mitigation Against DPRK Crypto Theft<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Despite the sophistication of the tactics, firms likely to be targeted can take various steps to mitigate their risks, the FBI said. These include developing their own in-house methods to verify a contact&#8217;s identity using separate unconnected communication platforms (such as a live video call on a different messaging app than the one used by the potential attacker).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations also should be careful not to store information about cryptocurrency wallets \u2014 such as logins, passwords, wallet IDs, seed phrases, private keys, etc. \u2014 on Internet-connected devices, where they are vulnerable. And employees should avoid taking pre-employment tests or executing code during any recruitment process on company-owned laptops or devices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Requiring multiple factors of authentication and approvals from several different unconnected networks prior to moving any financial assets to someone also is a best practice that can help any organization avoid being defrauded by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/north-korean-state-actors-attack-critical-bug-in-teamcity-server\" rel=\"noopener\">savvy state-sponsored actors<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, according to the FBI.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-north-korean-actors-aggressive-cyberattack-wave\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean threat actors are expected to launch imminent attacks<\/p>\n","protected":false},"author":12,"featured_media":5141,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/fbi-north-korean-actors-readying-aggressive-cyberattack-wave.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5140"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5140\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5141"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}