N Korean hackers are working with Eastern European cybercriminals: report

13-Dec-2019 Intellasia | Reuters | 6:02 AM Print This Post

North Korean state-backed hackers appear to be cooperating with Eastern European cybercriminals, a report here said on Wednesday, a finding that suggests digital gangsters and state-backed spies are finding common ground online.

Mountain View, California-based SentinelOne says that the Lazarus Groupwhich American prosecutors accuse of organising the leak of emails from Sony Pictures and stealing millions of dollars from the Central Bank of Bangladeshis getting access to some of its victims through a cybercrime gang dubbed “TrickBot.”

“For me it’s the biggest crimeware story since I don’t-know-when,” said Vitali Kremez of SentinelOne. “The Lazarus group has a relationship with the most sophisticated, most resourceful Russian botnet operation on the landscape.”

Hints that Lazarus and TrickBot operators are cooperating had surfaced previously. In April, a BAE researcher said here she and others were weighing theory that the cybercriminals were selling access to compromised organisations to Lazarus, a bit like a fence selling stolen doorkeys to a burglar.

An illustration picture shows a projection of binary code including cyrillic words around the shadow of a man, taken in Warsaw October 8, 2014. (Reuters)

An illustration picture shows a projection of binary code including cyrillic words around the shadow of a man, taken in Warsaw October 8, 2014. (Reuters)

In July, the cybersecurity arm of Japanese telecommunications company NTT speculated here that North Korea might be collaborating with Lazarus and TrickBot’s operators.

Kremez said he found evidence. TrickBot communicated with a Lazarus-controlled server just a couple of hours before that same server was used to help break into the Chilean interbank network earlier this year, he said. American officials have also blamed the multimillion dollar heist on North Korea.

“That’s the strongest possible evidence linking to a celebrated case of Lazarus intrusion,” said Kremez.

Kremez said that the TrickBot operators were likely renting out its services to the North Koreans, or perhaps working on a commission basis.

The judgment was seconded by Assaf Dahan of Boston-based Cybereason, which is publishing its own, separate report here on Trickbot’s operations Wednesday. He reviewed SentinelOne’s research and said its conclusions were credible, adding that he was certain that the cybercriminals knew that they were dealing with the North Korean government.

“Whether they care or not is a different thing,” he said.

https://www.reuters.com/article/us-usa-cyber-north-korea/north-korean-hackers-are-working-with-eastern-european-cybercriminals-report-idUSKBN1YF1KA

 


Tags:

Category: Korea

Print This Post