No Good Deed goes Unpunished

10913167469?profile=RESIZE_400xSometimes, good intentioned research can actually benefit adversaries.  Recently when a US-based foreign affairs analyst, received an email from the Director of the “38 North think-tank” to commission an article, it seemed to be business as usual.  The sender was actually a suspected North Korean spy seeking information, according to those involved and three cybersecurity researchers.

Instead of infecting his computer and stealing sensitive data, as hackers typically do, the sender appeared to be trying to elicit his thoughts on North Korean security issues by pretending to be 38 North director Jenny Town.  "I realized it wasn't legit once I contacted the person with follow up questions and found out there was, in fact, no request that was made, and that this person was also a target," said the analyst.  "So, I figured out pretty quickly this was a widespread campaign."

This email instance is part of a new and previously unreported campaign by a suspected North Korean hacking group, according to the cybersecurity experts, five such targeted individuals and emails seen by journalists.  Many cybersecurity experts suspect the hackers are targeting people who are influential in foreign governments to better understand where Western policy is headed on North Korea.

The hacking group, which researchers call Thallium or Kimsuky, among other names, has long used “spear-phishing” emails that trick targets into giving up passwords or clicking attachments or links that load malware.  It also appears to simply ask researchers or other experts to offer opinions or write reports.  According to emails recently seen, among the other issues raised, were China’s reaction in the event of a new nuclear test; and whether a "quieter" approach to North Korean "aggression" might be warranted.  "The attackers are having a ton of success with this very, very simple method," said the Microsoft Threat Intelligence Center (MSTIC), who added that the new tactic first emerged in January.  "The attackers have completely changed the process." MSTIC said it had identified "multiple" North Korea experts who have provided information to a Thallium attacker account.

A 2020 report by US government cybersecurity agencies said Thallium has been operating since 2012 and "is most likely tasked by the North Korean regime with a global intelligence gathering mission."  Thallium has historically targeted government employees, think tanks, academics, and human rights organizations, according to Microsoft.[1]  "The attackers are getting the information directly from the horse's mouth, if you will, and they don't have to sit there and make interpretations because they're getting it directly from the expert," MS said.

North Korean hackers are well-known for attacks netting millions of dollars, targeting Sony Pictures over a film seen as insulting to its leader, and stealing data from pharmaceutical and defense companies, foreign governments, and others.

North Korea's embassy in London did not respond to a request for comment, but it has denied being involved in cybercrime.  In other attacks, Thallium and other hackers have spent weeks or months developing trust with a target before sending malicious software, said the principal threat intelligence analyst at BAE Systems Applied Intelligence. 

But according to Microsoft, the group now also engages with experts in some cases without ever sending malicious files or links even after the victims respond.  This tactic can be quicker than hacking someone's account and wading through their emails, bypasses traditional technical security programs that would scan and flag a message with malicious elements, and allows the spies direct access to the experts' thinking, MS said.  "For us as defenders, it's really, really hard to stop these emails," he said, adding that in most cases it comes down to the recipient being able to figure it out.  BAE said some messages purporting to be from her had used an email address that ended in ".live" rather than her official account, which ends in ".org", but had copied her full signature line.  In one case, she said, she was involved in a surreal email exchange in which the suspected attacker, posing as her, included her in a reply.

A fellow with Defense Priorities and a columnist for several newspapers, said the emails he has received were written as if a researcher were asking for a paper submission or comments on a draft.  "They were quite sophisticated, with think tank logos attached to the correspondence to make it look as if the inquiry is legitimate," he said.   About three weeks after receiving the faked email from 38 North, a separate hacker impersonated him, emailing other people to look at a draft, he said.  That email, which DePetris shared with Reuters, offers US$300 for reviewing a manuscript about North Korea's nuclear program and asks for recommendations for other possible reviewers.  MS said the hackers never paid anyone for their research or responses and would never intend to.

Impersonation is a common method for spies around the world, but as North Korea's isolation has deepened under sanctions and the pandemic.  Western intelligence agencies believe Pyongyang has become particularly reliant on cyber campaigns, one security source in Seoul said, speaking on condition of anonymity to discuss intelligence matters.

In a March 2022 report, a panel of experts that investigates North Korea's UN sanctions evasions listed Thallium's efforts as among activities that "constitute espionage intended to inform and assist" the country's sanctions avoidance.  Town said in some cases, the attackers have commissioned papers, and analysts had provided full reports or manuscript reviews before realizing what had happened.

Defense Priorities said the hackers asked him about issues he was already working on, including Japan's response to North Korea's military activities.  Another email, purporting to be a reporter from Japan's Kyodo News, asked a 38 North staffer how they thought the war in Ukraine factored in North Korea's thinking, and posed questions about US, Chinese, and Russian policies.  "One can only surmise that the North Koreans are trying to get candid views from think tankers in order to better understand US policy on the North and where it may be going," they said.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@wapacklabs.com      

Weekly Cyber Intelligence Briefings:

  • Reporting: https://www. redskyalliance. org/   
  • Website: https://www. wapacklabs. com/  
  • LinkedIn: https://www. linkedin. com/company/64265941   

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/5504229295967742989

[1] https://www.reuters.com/world/asia-pacific/north-korean-cyber-spies-deploy-new-tactic-tricking-foreign-experts-into-writing-2022-12-12/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!