EXECUTIVE SUMMARY
The North Korean hacking organizations, particularly Kimsuky and Andariel, have increasingly targeted South Korea's construction and machinery sectors. These attacks align with North Korea's strategic policy focus on local industrial development and modernization. With North Korea’s heightened emphasis on construction and machinery, it is crucial to address the emerging cyber threats aimed at this industry. The ongoing attacks exploit vulnerabilities in local development and industrial operations, posing significant risks to public and private sectors.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The North Korean hacking organizations, particularly Kimsuky and Andariel, have increasingly targeted South Korea's construction and machinery sectors. These attacks align with North Korea's strategic policy focus on local industrial development and modernization. With North Korea’s heightened emphasis on construction and machinery, it is crucial to address the emerging cyber threats aimed at this industry. The ongoing attacks exploit vulnerabilities in local development and industrial operations, posing significant risks to public and private sectors.[emaillocker id="1283"]
The hacking organizations have employed various tactics, techniques, and procedures to execute their attacks. In one case, the Reconnaissance General Bureau Mountains and Rivers exploited vulnerabilities in a professional organization's website to distribute malware. This malware was hidden within modified security authentication software, which, when installed, enabled unauthorized access and data theft. The malware, written in Go programming language, was capable of capturing system information, screen data, and browser credentials. Another example involves Andariel exploiting vulnerabilities in domestic information security software, such as VPN and server security products. By replacing legitimate update files with malware and leveraging insufficient communication protocol validation, Andariel's DoraRAT was distributed. This remote-control malware facilitated unauthorized access, file manipulation, and data exfiltration.
The increasing frequency and sophistication of North Korea's cyber-attacks on South Korea's construction and machinery sectors underscore the need for enhanced security measures. These attacks exploit vulnerabilities in widely used software and target critical infrastructure, aiming to steal valuable information that could advance North Korea's industrial and military objectives. To mitigate these risks, it is crucial for organizations to implement continuous security training, maintain up-to-date software versions, enforce strict software distribution policies, and prioritize the security of supply chains. The Information Community urges all relevant stakeholders to take immediate action to protect against these ongoing threats and to ensure the integrity of their cyber defenses.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1189 | Drive-by Compromise |
| T1195 | Supply Chain Compromise | |
| Execution | T1204 | User Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| Discovery | T1083 | File and Directory Discovery |
| T1217 | Browser Information Discovery | |
| Collection | T1005 | Data from Local System |
| T1074 | Data Staged | |
| T1113 | Screen Capture | |
| T1119 | Automated Collection | |
| Command and Control | T1071 | Application Layer Protocol |
| T1573 | Encrypted Channel | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-vpn-update-flaw-to-install-malware/