
                                                                                                 North Korean hackers sent almost 900 spear phishing emails to South Korean foreign policy experts this year and attacked the country's online shopping malls to demand cyber assets, according to the National Police Agency. Gettyimagesbank
North Korean hackers sent almost 900 spear phishing emails to South Korean foreign policy experts this year and attacked the country's online shopping malls to demand cyber assets, according to the National Police Agency. Gettyimagesbank

Police say almost 900 received phishing emails, and some ended up paying ransom

By Ko Dong-hwan

North Korean carried out cyberattacks on at least 892 foreign policy experts from South Korea to steal their personal data and email lists as well as carrying out ransomware attacks against online malls, according to the National Police Agency. The South Korean authorities said Sunday that the attacks were meticulous enough to have tricked some of the victims into signing into fake websites, exposing their login details to the attackers.

The attacks, mainly targeting think tank experts and professors, began as early as last April, the agency said. The hackers sent spear phishing emails from multiple accounts posing as figures in South Korea, including a secretary from the office of Rep. Tae Yong-ho of the ruling People Power Party (PPP) in May, and an official from the Korea National Diplomatic Academy in October. The emails included a link to a fake website or an attachment carrying a virus that is triggered when opened.

"Even I was surprised by how the email looked so real," said Rep. Tae, a North Korean defector, in a press conference he hosted at the National Assembly on Sunday. "At first I thought it was sent by my office and I asked my secretary to verify it."

Forty-nine of the recipients ended up visiting the fake websites and logging in, allowing the hackers to infiltrate and monitor their email accounts and download data from them, the agency said.

The police said that the hackers laundered their IP addresses and employed 326 "detour" servers in 26 countries to make it difficult to trace them online.

The police suspect that the hackers are the same group that hacked Korea Hydro & Nuclear Power in 2014. The authorities pointed to the IP addresses indicating the origin of attack, the hackers' attempts to coax their targets into signing up for foreign websites, how the hackers infiltrated and managed the detour servers, the hackers' use of North Korean diction, as well as the fact the hackers targeted experts of diplomacy, inter-Korean unification, national security and defense as reasons to believe so. The police mentioned they investigated a North Korean hacking group called Kimsuky numerous times.

                                                                                                 North Korean hackers sent almost 900 spear phishing emails to South Korean foreign policy experts this year and attacked the country's online shopping malls to demand cyber assets, according to the National Police Agency. Gettyimagesbank
Paik Jong-wook from the National Intelligence Service speaks during a press conference at a national cybersecurity cooperation center in Seongnam, Gyeonggi Province, Dec. 22. Courtesy of National Intelligence Service

The police also said this year was also the first time they detected North Korean hackers using ransomware, which encrypts the files of the target device and demands a ransom for unlocking them. Apart from sending emails to the foreign policy experts, the hackers attacked shopping malls with cybersecurity vulnerability. Nineteen servers operated by 13 companies were hit and two of the businesses paid 2.5 million won ($1,980) worth of bitcoins to the group as a ransom.

Lee Gyu-bong, chief of the police agency's counter cyber terror bureau, said it has been tracking the email addresses from which the spear phishing mails were sent as well as inspecting bitcoin exchange markets overseas.

The police suspect that North Korean hackers' activities will continue for some time and urged people to increase security for their email accounts and other personal databases.

In a press conference last Thursday, the National Intelligence Service (NIS) also predicted Pyongyang's cyberattacks to continue next year. Forecasting potential threats to the country's cybersecurity in 2023, Paik Jong-wook, one of the deputy presidents of the NIS, said that state-backed hackers like those from North Korea and China will continue their attacks on Seoul to steal South Korean technologies related to the nuclear industry, space, semiconductors, national defense and joint strategies with the U.S. against Pyongyang.

"North Korean hackers might use deepfakes to produce and spread fake videos online as propaganda against Seoul, just like how Ukrainian President Zelenskyy was portrayed in a fake video surrendering to Russia in the early phase of the ongoing war," Paik said. "We consider smartphones, computers and other personal devices of the president and ministers primary targets to protect from those hackers."

Paik said North Korean hackers are trained to have the world's top capabilities to infiltrate virtual assets like digital coins. He assumed Pyongyang has stolen some 1.5 trillion won in cryptocurrency around the world since 2017, including 80 million won this year alone, and more than 10 million won from South Korea.

"There were an average of 1.18 million attempted cyberattacks by organized hackers from across the world against the South Korean government per day last month," Paik said. "It's no longer true that this volume of online attacks can be prevented singularly by the government."

The NIS on Nov. 30 introduced a new cybersecurity cooperation center so that the government and private cybersecurity providers can work jointly to protect against cyberattacks around the clock.
軟件大小1.00 MB
更新時間  2023.02.02
26日,電影《滿江紅》官微針對“《滿江紅》被指幽靈場、偷票房、買票房、資本操控、抄襲”等網絡傳言進行回應并嚴正聲明:均為無稽之談。對于上述傳聞《滿江紅》各出品方正在收集證據,并已開始依法通過訴訟等方式 ...
飛象網訊計育青/文)中科院高能物理研究所,是國際領先的高能物理研究基地之一,擁有一系列世界領先的大科學裝置和重要實驗。每時每刻,都有海量的科研數據從全國各地的試驗裝置生成,傳輸、匯聚到計算中心進行存儲 ...
當游戲開發商與發行商簽合同的時候,他們必須得先搞清楚合同上的細則、估算自己能夠獲得的收益。但是,發行商優勢如何處理游戲銷售所得分成的呢?他們如何持續開展業務?開發者又如何知道自己這筆錢花得冤不冤?近日 ...


塔迪奇:球隊太多次浪費優勢局面 施魯德是好教練但這就是足球
塔迪奇:球隊太多次浪費優勢局面 施魯德是好教練但這就是足球1月27日訊 荷甲豪門阿賈克斯近來狀態糟糕,近七輪聯賽6平1負未嘗勝績,在本輪主場1-1被福倫丹逼平后,球隊正式解雇了僅執教半年的主帥施魯德。阿賈克斯隊長塔迪奇在本場賽后接受了采訪,塞爾維亞人在采訪中
[INTERVIEW] 'There is opportunity in every crisis,' says Yoido Full Gospel Church pastor
[INTERVIEW] 'There is opportunity in every crisis,' says Yoido Full Gospel Church pastorYoido Full Gospel Church senior pastor Lee Young-hoon poses during an interview with The Korea Times


莊浪:科技創新賦能“慧”就產業強農路  近年來,莊浪縣堅持把推行科技特派員制度作為服務鄉村振興的重要工作來抓,創新體制機制、建設科技平臺、打造科技品牌,選派441名種技特派員到
多國語言[中文]. 1.00 MBM · 電影《無名》1月17日在北京舉辦“請留意”發布會,博納影業集團董事長、影片出品人及總制片人于冬,總監制蔣德富,導演及編劇程耳,演員王一博、黃磊、大鵬、王傳君、張婧儀出席現場活動,令現場掀起熱浪。對于網 ...
  • 多國語言[中文]. 1.00 MBM · 氣血對于女人來講是十分重要,因為氣血是直接關乎女性的身體健康,以及反映女性的容貌氣色。“女人是水做的”水乃氣血,機體的營養物質需要由血來供給,而氣可以推動血的運行,讓血輸送到身體各處,兩者相互依賴,氣 ...
  • 多國語言[中文]. 1.00 MBM · 由貓槍工作室研發,嗶哩嗶哩游戲代理的回合制二次元卡牌手游《非匿名指令》已經在 11 月開啟了全平臺公測。在近未來都市風的游戲世界中玩家需要作為“代行者”,游走于勢力間的制衡與斗爭,踏上暗流涌動的征途。 ...
  • 多國語言[中文]. 1.00 MBM · 今日,電影《長空之王》發布新海報,戰機之下,是雄鷹振翅翱翔!影片將于2023年上映,具體日期仍未公布。新海報:影片原定于去年國慶檔9月30日上映,不過官方于27日突然宣布改檔。電影《長空之王》由劉曉世 ...
  • 购彩助手-官网 大发11选5-手机版 彩乐园-通用app下载 万家彩票(上海)集团有限公司 快彩网(北京)集团有限公司 彩人间(浙江)集团有限公司 民彩网(广东)集团有限公司