Threat Advisory

North Korean Hackers Exploit VPN Flaws to Deploy DoraRAT Malware

Threat: Ransomware
Targeted Region: South Korea
Threat Actor Region: North Korea
Targeted Sector: Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The North Korean hacking organizations, particularly Kimsuky and Andariel, have increasingly targeted South Korea's construction and machinery sectors. These attacks align with North Korea's strategic policy focus on local industrial development and modernization. With North Korea’s heightened emphasis on construction and machinery, it is crucial to address the emerging cyber threats aimed at this industry. The ongoing attacks exploit vulnerabilities in local development and industrial operations, posing significant risks to public and private sectors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The North Korean hacking organizations, particularly Kimsuky and Andariel, have increasingly targeted South Korea's construction and machinery sectors. These attacks align with North Korea's strategic policy focus on local industrial development and modernization. With North Korea’s heightened emphasis on construction and machinery, it is crucial to address the emerging cyber threats aimed at this industry. The ongoing attacks exploit vulnerabilities in local development and industrial operations, posing significant risks to public and private sectors.[emaillocker id="1283"]

 

The hacking organizations have employed various tactics, techniques, and procedures to execute their attacks. In one case, the Reconnaissance General Bureau Mountains and Rivers exploited vulnerabilities in a professional organization's website to distribute malware. This malware was hidden within modified security authentication software, which, when installed, enabled unauthorized access and data theft. The malware, written in Go programming language, was capable of capturing system information, screen data, and browser credentials. Another example involves Andariel exploiting vulnerabilities in domestic information security software, such as VPN and server security products. By replacing legitimate update files with malware and leveraging insufficient communication protocol validation, Andariel's DoraRAT was distributed. This remote-control malware facilitated unauthorized access, file manipulation, and data exfiltration.

 

The increasing frequency and sophistication of North Korea's cyber-attacks on South Korea's construction and machinery sectors underscore the need for enhanced security measures. These attacks exploit vulnerabilities in widely used software and target critical infrastructure, aiming to steal valuable information that could advance North Korea's industrial and military objectives. To mitigate these risks, it is crucial for organizations to implement continuous security training, maintain up-to-date software versions, enforce strict software distribution policies, and prioritize the security of supply chains. The Information Community urges all relevant stakeholders to take immediate action to protect against these ongoing threats and to ensure the integrity of their cyber defenses.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access  T1189 Drive-by Compromise
 T1195 Supply Chain Compromise
 Execution T1204 User Execution
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
Discovery T1083 File and Directory Discovery
T1217 Browser Information Discovery
Collection T1005 Data from Local System
 T1074 Data Staged
T1113 Screen Capture
 T1119 Automated Collection
Command and Control T1071 Application Layer Protocol
 T1573 Encrypted Channel
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-vpn-update-flaw-to-install-malware/

[/emaillocker]
crossmenu