23 April 2024

North Korean hackers target South Korean defense contractors


North Korean hackers target South Korean defense contractors

South Korea's police have disclosed that North Korean hacking groups have been carrying out extensive cyber attacks against South Korean defense companies for over a year, resulting in the breach of internal networks and theft of technical data, Reuters reported.

South Korea has emerged as a significant global defense exporter in recent years, securing contracts worth billions of dollars for military equipment such as mechanized howitzers, tanks, and fighter jets.

The hacking teams, believed to be affiliated with North Korea's intelligence apparatus, including groups known as Lazarus, Kimsuky, and Andariel, have been identified as the perpetrators behind these cyber intrusions described as “all-out” by authorities. According to police reports, the attackers deployed malware into the data systems of defense companies, either directly or through contractors associated with them.

Working in collaboration with experts from the national spy agency and the private sector, law enforcement officials were able to trace the origin of the hacks. They identified the hacking groups based on source IP addresses, signal re-routing architecture, and malware signatures used in the attacks.

One notable incident cited by authorities occurred in November 2022, where hackers implanted a code into a company's public network. This code then spread to the intranet when the internal security system was momentarily disabled for a network test.

Additionally, hackers exploited security vulnerabilities introduced by subcontractors who utilized identical passcodes for both personal and official email accounts, gaining unauthorized access to defense company networks and exfiltrating confidential technical data.


Back to the list

Latest Posts

Cyber Security Week in Review: May 3, 2024

Cyber Security Week in Review: May 3, 2024

In brief: the Dropbox breach, Chinese hackers caught manipulating China’s Great Firewall, REvil hacker sentenced, and moreю
3 May 2024
REvil hacker sentenced to 13 years for $700M ransomware spree

REvil hacker sentenced to 13 years for $700M ransomware spree

In addition to his prison sentence, Vasinskyi was ordered to pay over $16 million in restitution.
2 May 2024
Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

The attackers accessed authentication tokens, MFA keys, hashed passwords, and customer info.
2 May 2024