The North Korean military's notorious hacking arm, known as the Lazarus Group, has been accused of targeting public and private sector research organizations, an Indian medical research company, and other businesses in the energy sector. Security analysts at WithSecure reported that they were called to respond to a cyberattack that was initially linked to the BianLian group, a ransomware gang that has been targeting the health care, education, insurance, and media industries since December 2021. Upon further investigation, however, they determined that several key factors pointed to Lazarus. The victims included a health care research organization in India, a manufacturer of technology used in energy, research, defense, and health care, as well as the chemical engineering department of a leading research university. The researchers named the campaign 'No Pineapple' due to an error message found in the code of a backdoor tool. The attackers were focused on intelligence gathering, and began with an attack on a company exploited through two bugs affecting the digital collaboration platform Zimbra. The hackers used the bugs to gain access to a Zimbra mail server and likely exfiltrated the contents of the mailboxes. By October 2022, the group had moved laterally to another vulnerable device on the network and used malware to steal 100 GB of data on November 5. The researchers attributed the attack to the Lazarus Group based on the malware used and several operational mistakes made by the group during their intrusion. The infrastructure used by the group during the attack has been linked to previous Lazarus campaigns identified by other security companies. The toolkit used by the threat actor is very similar to other reported instances of North Korean groups, and the hours of operation suggest that the attack was initiated by a North Korean state actor. WithSecure analysts were able to tie the campaign to several other victims after an investigation. In April 2022, the U.S. State Department offered a reward of up to $5 million for information about actors connected to North Korean digital operations that help keep the regime afloat and fund its weapons programs. The Lazarus Group and other North Korean military arms are accused of being responsible for $1.7 billion worth of cryptocurrency theft in 2022. The U.S. Treasury has openly accused North Korea of being involved in the $100 million hack of Harmony Bridge and of orchestrating the attack on Axie Infinity's Ronin Network, which saw almost $600 million in cryptocurrency stolen.
This Cyber News was published on therecord.media. Publication date: Fri, 03 Feb 2023 12:28:02 +0000