Friday, June 13, 2025
LBNN
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • Documentaries
No Result
View All Result
LBNN

Set your email servers to block N. Korean spies, US officials urge

Simon Osuji by Simon Osuji
May 3, 2024
in Military & Defense
0
Set your email servers to block N. Korean spies, US officials urge
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


A North Korean hacking collective is leveraging poorly configured email security protocols to deploy phishing attacks against academic institutions, think tanks, journalists and nonprofit organizations, U.S. agencies warned Thursday.

The group, known as Kimsuky, is using enhanced phishing tactics underpinned by the configuration flaws, allowing them to surreptitiously gain access to organizations’ email domains and masquerade as legitimate users, according to the advisory, which is headed by the State Department, FBI and NSA.

Related posts

How SADI can leverage local capabilities for global impact

How SADI can leverage local capabilities for global impact

June 13, 2025
How drone warfare fares in the 2026 budget

How drone warfare fares in the 2026 budget

June 13, 2025

Kimsuky is a cybercrime unit believed to be housed in the DPRK’s military intelligence directorate, known as the Reconnaissance General Bureau, or RGB. It has taken on other names from private sector cybersecurity researchers, including Emerald Sleet, APT43 and Velvet Chollima.

The phishing messages are sent as malicious emails. Once communication is established between a legitimate user and the disguised hacker, the latter sends follow-up replies containing malign links and attachments that can siphon recipients’ sensitive data.

In one instance, a Kimsuky operative posed as a journalist seeking comment on geopolitical issues related to North Korea. Because of improper configuration, the bogus reporter was able to change the “Reply-to” email address so that the targeted account’s responses would be sent to a North Korean-controlled account.

The exploit is rooted in the Domain-based Message Authentication, Reporting and Conformance, or DMARC, a protocol that gives system administrators the ability to control unauthorized use of email domains to prevent spoofing and phishing attempts.

Certain signs can help targeted orgs spot the sham emails, including typos, awkward English-speaking sentence structure and repeated email text found in previous engagement with other victims, the advisory says. But it also urges institutions to change their DMARC policies, like re-coding configurations to confine messages that don’t match account domains or label them as spam.

North Korea has deployed shadow operatives across the globe who pose as legitimate IT workers, planting themselves into companies to carry out long-haul schemes that fund Pyongyang’s nuclear weapons program. They’ve been able to finance the programs through covert cryptocurrency transactions, and the schemes have paid for some 50% of the DPRK’s missile projects, according to public U.S. assessments.

The Kimsuky entity, in particular, focuses on providing “stolen data and valuable geopolitical insight to the North Korean regime by compromising policy analysts and other experts,” the readout says.

The intelligence-gathering collective has been active since at least 2012, cyber officials have previously stated. 

The Treasury Department in November sanctioned eight North Korean agents that enabled revenue generation for the nation’s nuclear missile activities, as well as Kimsuky, on grounds that the group carried out intelligence-gathering activities in support of Pyongyang’s national interests. 

The nation’s cyber forces have matured and will “continue its ongoing cyber campaign, particularly cryptocurrency heists; seek a broad variety of approaches to launder and cash out stolen cryptocurrency; and maintain a program of IT workers serving abroad to earn additional funds,” a February U.S. intelligence assessment says. 





Source link

Previous Post

Beware of AI-based deception detection, warns scientific community

Next Post

New Airbnb ‘Icon’ Stays Include the ‘Up’ House, Purple Rain

Next Post
New Airbnb ‘Icon’ Stays Include the ‘Up’ House, Purple Rain

New Airbnb 'Icon' Stays Include the 'Up' House, Purple Rain

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Diamond Offshore Drilling Wins Drillship Contract in Guinea-Bissau

Diamond Offshore Drilling Wins Drillship Contract in Guinea-Bissau

2 years ago
Eurus Energy invest in Pentland Floating Offshore Wind Farm

Eurus Energy invest in Pentland Floating Offshore Wind Farm

12 months ago
Investable Green Industrial Cities Standards previewed at COP28 Africa Investment Earthshot Summit

Investable Green Industrial Cities Standards previewed at COP28 Africa Investment Earthshot Summit

1 year ago
Top 10 African countries the United States promised the most money in 2024

Top 10 African countries the United States promised the most money in 2024

1 month ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0
  • Matthew Slater, son of Jackson State great, happy to see HBCUs back at the forefront

    0 shares
    Share 0 Tweet 0
  • Dolly Varden Focuses on Adding Ounces the Remainder of 2023

    0 shares
    Share 0 Tweet 0
  • US Dollar Might Fall To 96-97 Range in March 2024

    0 shares
    Share 0 Tweet 0
  • Privacy Policy
  • Contact

© 2023 LBNN - All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • Documentaries
  • Quizzes
    • Enneagram quiz
  • Newsletters
    • LBNN Newsletter
    • Divergent Capitalist

© 2023 LBNN - All rights reserved.