Story image

Lazarus Group almost certainly connected to North Korea, Group-IB alleges

31 May 2017

Threat intelligence agency Group-IB has published research indicating that the notorious Lazarus Group is well and truly connected to North Korea.

The group has been behind numerous attacks, including one that tried to steal US$1 billion from the Central Bank of Bangladesh. It compromised Polish banks in the process, and Group-IB says that attack was connected to Noth Korea.

The group was also behind the Sony Pictures hack in 2014, and numerous attacks on the South Korean Government.

Group-IB says that detailed analysis of the criminals' Command & Control (C&C) infrastructure and combined threat intelligence pinpointed the group's attacks to Pyongyang.

Further allegations also suggest that the group is controlled by Bureau 121, a division of North Korean intelligence agency Reconnaissance General Bureau.

Group-IB says that its report focused on infrastructure research, rather than malware analysis or attribution that previous reports have used.

The researchers found a 'complex' three-layer architecture, encrypted channels, VPN services and other techniques, but still managed to identify the group's operating location.

Group-IB co-founder and head of Threat Intelligence Department Dmitry Volkov, says the Lazarus Group is thorough and careful.

"Our research testified that North Korean Lazarus group is taking extraordinary precaution measures, dividing the attacks into several stages and launching all the modules manually. So that even if the attack is detected, it would take security researchers much time and effort to investigate it. To mask malicious activity, the hackers used a three-layer C&C infrastructure and pretended to be Russians," he explains.

The group has been using IP addresses across the world, including those of universities in the US, Canada, India and Great Britain, as well as pharmaceutical companies in Japan and China. They have also been using government subnets in various countries, Group-IB says.

"Taking into consideration strengthening economic sanctions against North Korea, as well as the geopolitical tension in the region, we expect a new wave of Lazarus attacks against global financial institutions. With that said, we strongly recommend the banks learn more about targeted attacks' tactics and techniques, increase corporate cybersecurity awareness, and cooperate with the companies providing relevant Threat Intelligence," Volkov adds.

Group-IB is a threat intellience provider with clients across the globe, including Fortune 500 companies in Asia and Australia.

Cryptomining apps discovered on Microsoft’s app store
It is believed that the eight apps were likely developed by the same person or group.
WhatsApp users warned to change voicemail PINs
Attackers are allegedly gaining access to users’ WhatsApp accounts by using the default voicemail PIN to access voice authentication codes.
Swiss Post asks public to hack its e-voting system
Switzerland’s postal service Swiss Post is inviting keen-eyed security experts and white hats to hack its e-voting system.
Spoofs, forgeries, and impersonations plague inboxes
It pays to double check any email that lands in your inbox, because phishing attacks are so advanced that they can now literally originate from a genuine sender’s account – but those emails are far from genuine.
Flashpoint signs on emt Distribution as APAC partner
"Key use cases that we see greatly benefiting the region are bolstering cybersecurity, combating insider threats, confronting fraud, and addressing supply chain risk, to name a few."
The attack surface: 2019's biggest security threat
As businesses expand, so does their attack surface – and that may be the biggest cybersecurity risk of them all, according to Aon’s 2019 Cyber Security Risk Report.
Opinion: Cybersecurity as a service answer to urgent change
Alan Calder believes a CSaaS model can enable a company to build a cyber resilience strategy in a coherent and consistent manner.
Why SD-WAN is key for expanding businesses - SonicWall
One cost every organisation cannot compromise on is reliable and quick internet connection.