CISA warns of BLINDINGCAN, a new strain of North Korean malware

4 years ago 135
BOOK THIS SPACE FOR AD
ARTICLE AD
north-korea-reportedly-stole-2b-in-wave-5d4d934316e22d00012a3ac5-1-aug-13-2019-12-43-01-poster.jpg

The US Cybersecurity and Infrastructure Security Agency (CISA) has published a security alert today containing details about a new strain of malware that was seen this year deployed by North Korean government hackers.

This new malware was spotted in attacks that targeted US and foreign companies active in the military defense and aerospace sectors, according to reports from McAfee (Operation North Star) and ClearSky (Operation DreamJob).

The attacks followed the same pattern, with North Korean hackers posing as recruiters at big corporations in order to approach employees at the desired companies.

Targeted employees were asked to go through an interviewing process, during which they'd usually receive malicious Office or PDF documents that North Korean hackers would use to deploy malware on the victim's computers.

The final payload in these attacks is the focal point of today's CISA alert, a remote access trojan (RAT) that CISA calls BLINDINGCAN (called DRATzarus in the ClearSky report).

CISA experts say North Korean hackers used the malware to gain access to victim's systems, perform reconnaissance, and then "gather intelligence surrounding key military and energy technologies."

This was possible due to BLINDINGCAN's broad set of technical capabilities, which allowed the RAT to:

Retrieve information about all installed disks, including the disk type and the amount of free space on the diskGet operating system (OS) version informationGet Processor informationGet system nameGet local IP address informationGet the victim's media access control (MAC) address.Create, start, and terminate a new process and its primary threadSearch, read, write, move, and execute filesGet and modify file or directory timestampsChange the current directory for a process or fileDelete malware and artifacts associated with the malware from the infected system

The CISA alert includes indicators of compromise and other technical details that can help system administrators and security professionals set up rules to scan their networks for signs of compromise.

This is the 35th time the US government has issued a security alert about North Korean malicious activity. Since May 12, 2017, CISA has published reports on 31 North Korean malware families on its website.

North Korean government hackers have been one of the four most active threat actors that have targeted the US in recent years, together with Chinese, Iranian, and Russian groups.

The US has been trying to dissuade attacks by criminally charging hackers from these countries or publicly calling out hacking activities that go beyond the real of intelligence espionage.

Earlier this year in April, the US State Department has stepped up its efforts to deter North Korean hacking by setting up a $5 million reward program for any information on North Korean hackers, their whereabouts, or their current campaigns.

In a report published last month, the US Army revealed that many of North Korea's hackers operate from abroad, not just from North Korea, from countries such as Belarus, China, India, Malaysia, and Russia.

Read Entire Article