🧐 ProPicks AI October update is out now! See which stocks made the listPick Stocks with AI

North Korean hackers are working with Eastern European cybercriminals: report

Published 12/11/2019, 10:53 AM
© Reuters. FILE PHOTO: An illustration picture shows a projection of binary code including cyrillic words around the shadow of a man

By Raphael Satter

(Reuters) - North Korean state-backed hackers appear to be cooperating with Eastern European cybercriminals, a report https://labs.sentinelone.com/the-deadly-planeswalker-how-the-trickbot-group-united-high-tech-crimeware-apt said on Wednesday, a finding that suggests digital gangsters and state-backed spies are finding common ground online.

Mountain View, California-based SentinelOne says that the Lazarus Group - which American prosecutors accuse of organizing the leak of emails from Sony Pictures and stealing millions of dollars from the Central Bank of Bangladesh - is getting access to some of its victims through a cybercrime gang dubbed "TrickBot."

"For me it's the biggest crimeware story since I don't-know-when," said Vitali Kremez of SentinelOne. "The Lazarus group has a relationship with the most sophisticated, most resourceful Russian botnet operation on the landscape."

Hints that Lazarus and TrickBot operators are cooperating had surfaced previously. In April, a BAE researcher said https://www.wired.com/story/atm-hacks-swift-network she and others were weighing the theory that the cybercriminals were selling access to compromised organizations to Lazarus, a bit like a fence selling stolen doorkeys to a burglar.

In July, the cybersecurity arm of Japanese telecommunications company NTT speculated https://technical.nttsecurity.com/post/102fnog/targeted-trickbot-activity-drops-powerbrace-backdoor that North Korea might be collaborating with Lazarus and TrickBot's operators.

Kremez said he found evidence. TrickBot communicated with a Lazarus-controlled server just a couple of hours before that same server was used to help break into the Chilean interbank network earlier this year, he said. American officials have also blamed the multimillion dollar heist on North Korea.

"That's the strongest possible evidence linking to a celebrated case of Lazarus intrusion," said Kremez.

Kremez said that the TrickBot operators were likely renting out its services to the North Koreans, or perhaps working on a commission basis.

The judgment was seconded by Assaf Dahan of Boston-based Cybereason, which is publishing its own, separate report https://www.cybereason.com/blog/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware on Trickbot's operations Wednesday. He reviewed SentinelOne's research and said its conclusions were credible, adding that he was certain that the cybercriminals knew that they were dealing with the North Korean government.

© Reuters. FILE PHOTO: An illustration picture shows a projection of binary code including cyrillic words around the shadow of a man

"Whether they care or not is a different thing," he said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.