|
News North Korean hackers target NK Pro readers with malicious websites, emails, docsKimsuky group aims to access subscriber content and gather intelligence with new phishing campaign, researchers find Hackers linked to North Korea’s Kimsuky group are trying to steal login credentials from NK Pro subscribers and collect technical details that can be used in future cyberattacks, an investigation in partnership with cybersecurity firm SentinelLabs reveals. The highly targeted phishing campaign likely represents a North Korean attempt to access reporting and data on the NK Pro website. According to SentinelLabs, gaining access to the platform would help North Korea better understand the level of information about the country that is available to the international community, as well as the conversations around it. Dennis Desmond, a cybersecurity lecturer at the University of the Sunshine Coast and a former U.S. counterintelligence officer, suggested the attackers may be looking for ways to interfere with media reporting about the country. “This looks like a targeted disruption campaign,” he told NK Pro. “Looks like [NK Pro] got under someone’s skin.” The findings add significant detail to the joint advisory issued last week by the U.S. Department of State, FBI, National Security Agency and several ROK agencies that described the hacking syndicate’s extensive spear-phishing campaigns. “By actively targeting high-profile experts in North Korean affairs and attempting to steal subscription credentials from prominent news and analysis outlets focussing on North Korea, Kimsuky demonstrates a heightened curiosity in understanding how the international community perceives developments concerning North Korea,” SentinelLabs senior threat researcher Aleksandar Milenkoski told NK Pro. “These actions are probably part of their broader objective to gather strategic intelligence, contributing to North Korea’s decision-making processes.” In one attack observed by NK Pro, hackers used the spoofed email address membership@nknews[.]pro to send emails about “updates for ip security” to subscribers, claiming to come from account manager Melanie Ivey. A link included in the email directs recipients to a malicious copy of the product login page that appears to send any entered credentials to the attackers, researchers at SentinelLabs said. In another attack, the hackers used the spoofed email address chad.ocarroll@nknews[.]pro to send a request for the review of a malicious document titled “North Korea’s Nuclear Threats: South Korean Perception and US Nuclear Extended Deterrence.” The attackers initially only included a link to what appeared to be a Google Docs document, but actually directed the recipient to a fake Google page likely designed to steal login credentials. “The URL’s destination is manipulated through the spoofing technique of setting the href HTML property to direct to a website created by Kimsuky,” Milenkoski explained in his report. “This method, commonly employed in phishing attacks, creates a discrepancy between the perceived legitimacy of the link (a genuine Google document) and the actual website visited upon clicking the URL.” The malicious Google Docs page even included the personal email address of the targeted individual to further create the impression of legitimacy. ![]() In another case seen by NK Pro, both the Google Doc and the attached Word document sent by the attackers were free of any malware — likely a strategy to build trust before replacing the links with malicious referrers that would direct the recipient to a web server controlled by the attackers. During a subsequent email exchange, the attackers eventually sent a compressed file named “NK_nuclear_threat.zip,” which contained a Microsoft Word document infected with the known ReconShark malware, SentinelLabs found. The ReconShark toolkit has previously been used by North Korean hackers to collect technical details about their victim’s computers to help with future cyberattacks. “This Kimsuky activity serves as an indication of the group’s growing efforts to establish early communication and foster trust with their targets prior to initiating malicious operations,” Milenkoski said. While Kimsuky has become known for investing significant time and resources in order to compromise particular individuals, these recent attacks highlight the group’s persistence and commitment, the cybersecurity researcher warned. Edited by Arius Derr © Korea Risk Group. All rights reserved. |







