US and allies accuse North Korean hackers of military espionage

July 27, 2024
1 min read

TLDR:

North Korean hackers, known as Anadriel or APT45, are stealing military secrets to support their nuclear weapons program. They have targeted defense and engineering firms, as well as NASA and U.S. Air Force bases. The hackers have used ransomware to target U.S. hospitals and healthcare companies, and the U.S. Justice Department has charged one suspect. The FBI is offering a $10 million reward for information leading to the suspect’s arrest.

Full Article:

North Korean hackers, identified as Anadriel or APT45, have been conducting a global cyber espionage campaign to steal classified military secrets in order to support Pyongyang’s nuclear weapons program, according to a joint advisory released by the United States, Britain, and South Korea. The hackers are believed to be part of North Korea’s intelligence agency, the Reconnaissance General Bureau, which was sanctioned by the U.S. in 2015. The cyber unit has targeted defense and engineering firms, including manufacturers of tanks, submarines, naval vessels, fighter aircraft, and missile and radar systems.

Victims in the U.S. have included NASA, Randolph Air Force Base in Texas, and Robins Air Force Base in Georgia. The hackers used a malware script to gain unauthorized access to NASA’s computer system for three months, extracting over 17 gigabytes of unclassified data in February 2022. The U.S. Justice Department has charged one suspect, Rim Jong Hyok, for conspiring to access computer networks in the U.S. and money laundering. Rim is believed to be in North Korea, and the FBI is offering a $10 million reward for information leading to his arrest.

In addition to stealing military secrets, the North Korean hackers have used ransomware to target U.S. hospitals and healthcare companies to fund their operations. The U.S. Justice Department has seized online accounts belonging to the hackers, including $600,000 in virtual currency that will be returned to victims of the ransomware attacks. The global cyber espionage operation conducted by the North Korean hackers shows their determination to pursue their military and nuclear programs.

Latest from Blog

Apache’s OFBiz gets new fix for RCE exploits

TLDR: Apache released a security update for OFBiz to patch vulnerabilities, including a bypass of patches for two exploited flaws. The bypass, tracked as CVE-2024-45195, allows unauthenticated remote attackers to execute code