Singapore Summit Back On, North Korean Hackers Still Relentless

By: - June 8, 2018

As the saga of America’s reconciliation with North Korea continues to surprise, federal agencies have uncovered the latest threat posed by Pyongyang’s cyber army. The diplomatic side of this story seems to be dramatic enough. One week after abruptly canceling a meeting with North Korean leader Kim Jong Un, President Donald Trump announced the historic summit set to take place on June 12 in Singapore is back on. With the diplomacy now seemingly back on a positive course, it seems a bit ironic that U.S. government cyber analysts are just now revealing a threat posed by North Korea’s notorious hacker teams.

On March 31, the National Cybersecurity and Communications Integration Center (NCCIC) issued a joint Technical Alert (TA) produced by the Department of Homeland Security (DHS) and the FBI. The document warned of recent “malicious cyber activity by the North Korean government” as part of an ongoing operation by Pyongyang sponsored hacker teams. For the past year, these series of hacks have been dubbed by U.S. investigators as Operation Hidden Cobra. In the latest identified activities of Hidden Cobra, the NCCIC states that hackers are using two pieces of malware—until now unobserved—to gain illicit access to private networks and exfiltrate data.

The first program, called Joanap, is a Remote Access Trojan (RAT) which, if successfully delivered, allows an attacker to take control of a user’s machine and run pretty much any operation they please. RATs are usually delivered via email phishing, relying on a victim to unknowingly download a file containing the malicious software.

(Credit: Facebook/Proofpoint)

Joanap is suspected of being used as both a means to extract files and other data, as well as a way of harnessing large numbers of computers worldwide to take part in bigger hacks that require a broad base of participating machines (such as a Distributed Denial of Service attack, for instance). According to NCCIC, so far, Joanap has been identified on 87 compromised network nodes in 17 countries including Brazil, China, Spain, Taiwan, Sweden, India, and Iran.

A second malware type was also discovered in the form of a Server Message Block (SMB) Worm. As its name might suggest, SMB Worms work by exploiting the Server Message Block, a protocol that enables different nodes on a network to share data. This function allows the Worm to spread rapidly to many different computers, potentially all over the world. When launched, this particular SMB Worm, named Brambul, attempts to gain access to user accounts and protected files via brute-force password attacks using a list of embedded passwords.

Considering that a large percentage of all successful hacks are the result of weak passwords that almost anyone can guess, this method can be devastatingly effective. Once Brambul gains unauthorized access, the malware communicates information about the victim’s systems back to Hidden Cobra hackers using email. The information includes the IP address and hostname, as well as the username and password of each target’s system.

The TA put out by NCCIC concluded by urging users to review their system protocols and consider improving some of their security practices such as patching their applications, as many of Hidden Cobra’s methods rely on exploiting program flaws.

Pyongyang’s Cyber Army

North Korea has been investing heavily in its cyber capabilities for more than a decade. A 2014 report by the South Korean government noted that North Korea had about 6,000 “cyber warfare troops.” At the time, the U.S. Cyber Command, established by the Obama administration in 2009, has around 700 military and civilian employees. Collectively, all cyber units in the entire U.S. military have a goal of maintaining around 6,200 personnel.

North Korea has succeeded in heavily masking its activities behind mysterious hacking groups. Often these groups consist of nothing more than fictitious names invented to hide activities of the North Korean government. Many of North Korea’s hacks made the news months, sometimes years before the events were linked back to their real perpetrators.

Over the past decade, North Korea has shown their hacking capabilities should not be taken lightly by the West. DPRK started off small, building their hacking portfolio. The first incident linked to the group was back in 2007 in an operation dubbed “Flame” that used rudimentary tools to infiltrate South Korean government sites. Slowly but surely, Pyongyang’s cyber army became more efficient—and more dangerous.

In the summer of 2009, the group executed a series of highly effective coordinated cyber attacks against major government, news media, and financial websites in South Korea and the United States. The sites of eleven South Korean organizations including the presidential Blue House, the Defense Ministry, the National Assembly, Shinhan Bank, Korea Exchange Bank and the country’s top Internet portal, Naver, went down or had access problems. In the United States, the Treasury Department, Secret Service, Federal Trade Commission and Transportation Department sites were all down at varying points throughout the operation.

Then in 2013, computer networks running three major South Korean banks and the country’s two largest broadcasters were paralyzed. The attacks left many South Koreans unable to withdraw money from ATMs, and news broadcasting crews were stuck staring at blank computer screens. This operation was a major milestone, as it showed the North possessed the tools to actually cause real-world disruption with a cyber attack. A year later, one of the most famous hacks in history was executed against Sony Pictures Entertainment. The company lost all control of their own network and ultimately suffered a systemwide data wipe. The attack has been widely attributed to the Lazarus Group, a known front of the North Korean government.

More recently, a hack against crypto-currency exchange Youbit resulted in the company declaring bankruptcy after seventeen percent of its assets were stolen. The WannaCry ransomware attack that devastated UK healthcare systems was a stark reminder that DPRK can wreak havoc through the digital sphere.

North Korea’s Hackers in the Age of Reconciliation

As North Korea and the West move slowly toward reconciliation, one would think that most of Pyongyang’s cyber warriors would be out of a job, or at least being a bit less active. The recent NCCIC report shows that North Korean hackers are as relentless as ever.

How should all this be taken in the context of moving forward in establishing ties with DPRK? Again, the cyber activity we are observing is not trivial. All of the signs point to long-term planning for sophisticated attacks, and the targeting of private citizens and corporations in the U.S. and around the world.

The short answer is that North Korea does not want to dispense with its leverage just yet. In the same way that Pyongyang will not give away its nukes without being fairly confident that it has achieved a diplomatic win (in the form of, say, economic packages and defense guarantees), so too, the government will not simply halt its cyber warfare without knowing it has really established a secure position for itself. Furthermore, the “vulnerability” of diplomatic talks very often triggers the development of a “contingency plan” for if/when things go south at the negotiating table.

In a way, keeping up its cyber campaign is one of the ways North Korea is hedging its bets.

Something to consider, is that despite all of the “activity” surrounding North Korea over the past year, no substantial changes have actually occurred in terms of U.S. policy. American sanctions against North Korea from the Obama era are still in place. Trump himself added to these economic restrictions in an Executive Order he signed last September. The Order allows the United States to cut from its financial system and/or freeze the assets of any companies, businesses, organizations and individuals trading in goods, services or technology with North Korea.

This was followed by yet another round of restrictions aimed at closing the “China loophole” that had allowed North Korea to soften the effects of sanctions until that point. Thus from North Korea’s perspective, they are far from being in the clear. Hidden Cobra will almost certainly continue until an accord strongly in North Korea’s favor begins to actually foment.

  • RSS WND

    • Mosquitoes swarm Texas town, officials blame one (not-so-real) reason
      (FOX NEWS) -- Officials are pointing the finger at climate change as a Texas town battles with another spring of exploding mosquito populations. "If you open the car door to go somewhere, you’ve got 10 mosquitoes inside," Mith Varley, a resident of the Houston suburb of Conroe, Texas, said of the issue, according to a… […]
    • Organ-transplant patients may also inherit their donor's personality, bizarre findings reveal
      (STUDY FINDS) -- A shocking study finds organ transplant recipients may end up with a lot more than just a new heart or kidney. According to researchers from the University of Colorado School of Medicine, the vast majority of these patients may end up inheriting the personality of their donor! Imagine waking up from surgery… […]
    • Dave Ramsey steps in to rescue pro-Israel conference after Nashville hotel cancels
      (DAILY WIRE) -- Personal finance expert Dave Ramsey is rescuing a pro-Israel conference from cancellation after a Nashville hotel backed out from hosting because of alleged threats by anti-Israel activists. When Ramsey heard that a Nashville hotel revoked access for the Israel Summit, an event scheduled for next week that will feature prominent Christians and… […]
    • Kansas City apologizes after revealing on social media where Chiefs kicker Harrison Butker lives
      (CHRISTIAN POST) -- Kansas City has apologized after a city government social media account revealed where Chiefs kicker Harrison Butker lives after a commencement speech he made last weekend advocating for traditional Catholic values drew national media attention. Butker gave the graduation address at Benedictine College in Atchison, Kansas on Saturday, sparking a media firestorm… […]
    • WATCH: Woman who prayed while dangling from bridge in truck credits Lord for rescue
      (FAITHWIRE) -- Newly released dashcam footage of an accident that left a massive semitruck dangling from a bridge earlier this year is going viral — and for good reason. WATCH: Heart-stopping dash cam video shows the moment a pickup truck hit a tractor-trailer, causing it to plow through a guardrail and dangle over the edge… […]
    • WATCH: Trans high-school runner born a boy claims girls' state title and crowd unloads
      (FOX NEWS) -- A high-school transgender runner was booed while being crowned as the Oregon Girls' 6A 200-meter state champion. Aayden Gallagher, of McDaniel High School, won the state title by two-tenths of a second. Gallagher was also booed while crossing the finish line of the race. Crowd immediately BOOS when trans runner beats out… […]
    • 'You were filming the wrong person': Fed-up mom pounces on 'peeping Tom' outside dressing room
      (FOX NEWS) -- A Colorado mother was not going to let an alleged peeping Tom escape after she says she caught him watching her change in a department store fitting room. The incident happened May 11 in Lakewood, Michelle Chandler told local FOX31. The unnamed mall store reportedly offers dressing rooms for both men and… […]
    • WATCH: Biden mocked after non-existent reaction to his motorcade in Dem-run city
      (FOX NEWS) -- Critics on social media dragged President Biden over video footage showing what appeared to be a small showing of supporters greeting the president’s motorcade in the deep blue city of Atlanta, where he held a fundraising event and delivered Morehouse College’s commencement speech. "Crooked Joe Biden – dazed and confused, as usual… […]
    • State put migrant children in hotels with sex offenders: Report
      By Katelynn Richardson Daily Caller News Foundation A Massachusetts agency reportedly housed homeless and migrant families with young children in the same hotels as registered sex offenders, according to the Boston Globe. The state placed hundreds of homeless migrant families in at least six locations with sex offenders convicted of crimes against children, including pornography,… […]
    • Billionaires who fund protests also paying bills for House Democrats
      [Editor's note: This story originally was published by Real Clear Wire.] By Susan Crabtree Real Clear Wire For President Biden and congressional Democrats, the fierce party division over the campus protests and the war in Gaza is full of warning signs during the 2024 election year. The unrest is unlikely to stop when universities break… […]
  • Enter My WorldView