Showing posts with label North Korea. Show all posts
Showing posts with label North Korea. Show all posts

Monday, January 22, 2018

Asian Bitcoin Exchanges as Potential Hacker Targets

North Korea has been identified as conducting multiple thefts of Bitcoin cryptocurrency in 2017. These thefts have involved spearphishing attacks against at least two Bitcoin exchanges in South Korea that resulted in compromises of their systems and the loss of millions of dollars in Bitcoin. This appears to be part of a major North Korean campaign to acquire Bitcoin as a way to raise hard currency. This campaign was active through at least, December 2017. Given the North Korean interest in Bitcoin and the success of their hacker efforts to date, other cryptocurrency exchanges in the region may also be at risk. As a guide to further monitoring of this situation, a listing of exchanges in South Korea and Japan was compiled. The Japanese list consists of those recently certified by the Japanese government and one that is still awaiting certification...READ MORE

Wapack Labs has cataloged and reported on cryptocurrency related targeting in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

North Korea’s Illegal Campaign to Acquire Bitcoin

North Korea has been identified as conducting multiple thefts of Bitcoin cryptocurrency in 2017. In conjunction with its identification as the actor behind the Wannacry ransomware, which was also an attempt to acquire Bitcoin, plus limited evidence of bitcoin mining, these actions indicate a major North Korean campaign is underway to acquire Bitcoin as a way to raise hard currency. North Korea was likely motivated to acquire Bitcoin, by any means, because of the currency’s rapidly increasing value in 2017, the possibility of hiding the thefts by converting Bitcoin into more obscure forms of cryptocurrency, and the convertibility of Bitcoin and these other cryptocurrencies to hard currency. While it is unusual for a nation-state to be involved in this type of theft, it is not much different from other North Korean criminal enterprises which have included cyber bank robbery, illegal weapons sales, and counterfeiting U.S. currency...READ MORE

Wapack Labs has cataloged and reported on North Korean cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, November 3, 2017

Russian ISP Doing Business with North Korea

On 01 Oct 2017, TransTeleCom, a Russian owned telecommunications company began routing North Korean Internet. TransTeleCom owns one of the largest fiber optic cable based networks in the world. It is a fully owned subsidiary of Russian Railways, a joint-stock company with 100 percent involvement under the Russian Ministry of Transport. North Korea’s external Internet connections were historically serviced by China Unicom, but will now be provided by both China Unicom and Russia’s TransTeleCom. IPv4 traffic route allocation is 60 percent through TransTeleCom and 40 percent through China Unicom. Unicom will continue providing 100 percent IPv6 routing for North Korea. The contract between TransTeleCom and North Korea was originally signed in 2009. The recent Russian telecommunications escalation seems to be in support of North Korea after U.S. Cyber Command Distributed-Denial-of-Service (DDoS) attacks. Having routes in both China and Russia limits North Korea’s dependence on any one country as they are currently facing intense geopolitical pressures. North Korea’s shift from being predominantly Chinese hosted, to Russian support, is primarily due to U.S. political pressure on China to sever ties with North Korea over the recent nuclear missile tests and China’s failure to protect North Korea from the recent U.S. DDoS attacks. TransTeleCom operates similarly to China Unicom, the current North Korean Internet Service Provider (ISP), which has fiber optics laid along China’s Sino-Korean Friendship Bridge. However, TransTelecom is believed to be delivering North Korea’s Internet over the Korea-Russia Friendship Bridge, the only crossable border between North Korea and Russia. Wapack Labs will continue to monitor malicious cyber activities out of North Korean netblocks....READ MORE

Wapack Labs has cataloged and reported on North Korean cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, August 24, 2017

China’s Position in the U.S. & North Korean Conflict

China is attempting to play a moderating role in the current conflict between the United States and North Korea over North Korea’s development of intercontinental nuclear missiles. China has argued for restraint on all sides, and signed the United Nations sanctions measure against North Korea on 5 August 2017. A review of Chinese statements in their own media on 14-16 August 2017 indicate China is standing by its sanctions pledge and sees some hope for easing of the crisis:
  • On 14 August China reaffirmed that it was imposing an import ban on coal, iron, iron ore, lead, lead ore and seafood from North Korea as a tool to bring Pyongyang back to negotiations.
  • Some Chinese coverage argued that North Korean threats were just a stratagem to entice the U.S. to cancel its joint military exercises with South Korea.
  • The enthusiasm for joining with the United States in pressuring North Korea may have been blunted somewhat by the White House order to start an investigation into Chinese trade practices.
  • As of 16 August, China appeared to see signs that the crisis was starting to ease, based on North Korean media coverage of Kim Jong-Un’s visit to its Strategic Force Command and the “delay” in any attack decision. 
In general, China has indeed taken upon itself a relatively neutral stance in this conflict. If they stand by their pledge to block key imports from North Korea, this could over time put real economic pressure on North Korea. Whether that would be enough pain to cause North Korea to curtail their weapons programs is still in doubt. China’s statement that it would not support a preemptive strike by North Korea on the U.S. may also help keep this crisis from escalating...READ MORE

Wapack Labs has cataloged and reported extensively on China, North Korea, and sanctions in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Wednesday, June 7, 2017

NK Lazarus Threat to the Financial Sector Remains High

Newly discovered Command & Control (C2) Internet Protocols (IPs) confirm the geolocation of North Korean threat actors, Lazarus Group; despite their deliberate attempts at misdirection. They are known for their custom-tailoring and reuse of code between malware families and campaigns. Since 2009, Lazarus Group has targeted Asian-based financial institutions, European and South American financial institutions, and media companies, such as Sony Pictures. Recent financial and trading sanctions, levied on North Korea, will increase the likelihood of attacks on financial sectors; similar to the documented attacks, leveraging the Society for Worldwide Interbank Financial Telecommunications (SWIFT), to compromise central banks...READ MORE

Wapack Labs has cataloged and reported extensively on financial compromise and the Lazarus Group in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, August 25, 2016

Iran & North Korea Expand Cyber Capabilities


www.defenseone.com

On 22 August 2016, Wapack Labs identified potential cyber threats and vulnerabilities to Western interests; threats which span numerous critical infrastructure sectors.  Iran and ally North Korea, continue to grow and expand their cyber capabilities.  We are providing this information for your situational awareness.



Publication date:                         24 August 2016

Handling requirements:               Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:           Iranian and NK Threat Actors

Actor Type:                                  Tier II & III            

Potential Targets:                        USA / International

Past Reporting:                            Red Sky Alliance: DOC 2326, DOC 2741, DOC 4166

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.