North Korea Getting Ready Wage A Global Cyber War, Experts Say

It’s no secret that North Korea has a cyber army working in the shadows to attack western interests. The cyber-attack against Sony Pictures Entertainment in 2014 made it clear that the nation had developed its cyber warfare capabilities much more than had been realized until then.

But now it appears that North Korea has set its sights on loftier goals, perhaps spreading chaos and even damage worldwide through a well-placed series of cyber-attacks on defense targets, industry and media.

Now, US-CERT and the Federal Bureau of Investigation have issued a series of warnings intended to provide the necessary information for organizations to prevent or reduce the likelihood of a successful North Korean infiltration.

North Korea cyberwar

However, it the warning may be too late for some organization because their networks have been infected by the components of Hidden Cobra, which refers to the collection of malware being used to attack targets in South Korea and elsewhere around the world.

Hidden Cobra is an umbrella operation that launches malware against a wide variety of targets that North Korea is studying, apparently for future action. According to Paul Innella, CEO of TDI Security based in Washington, the goal of the Hidden Cobra operation appears to have changed. He said that North Korea has moved from running ransomware operations to something more sinister – information gathering.

“A lot of it is polling information on network infrastructure data,” Innella explained. “They’re trying to map out what we have.” He said that this operation already resulted in a breach that compromised planning between the military of South Korea and the United States.

Innella said that there’s been discussion recently about recent failures of North Korean rocket launches and whether those failures occurred as a result of cyber-attacks by the west. He said that it appears that the North Korean effort to map out the infrastructure of organizations in the west is a precursor to cyber-war.

Initially the attacks are likely to be against the military or launch systems, Innella said. But the plans of the North Koreans apparently go beyond that. The warnings from the Department of Homeland Security through US-CERT and the FBI indicate that there are also plans to attack the financial sector, aerospace and telecommunications using its FallChill malware, which is part of Hidden Cobra.

FallChill is a remote administration tool that evades detection by encrypting its communications traffic using TLS (transport layer security). The malware is able to use its remote administration capabilities to map out a network and then to report what it finds. The idea is that once FallChill has mapped out the networks (including the defenses) North Korea will know what and where to attack for best effect.

Originally published on eWeek

Continues on Page 2…

Page: 1 2

Wayne Rash

Wayne Rash is senior correspondent for eWEEK and a writer with 30 years of experience. His career includes IT work for the US Air Force.

Recent Posts

Tesla Shares Surge On China Advanced Self-Driving Push

Tesla makes key advances toward advanced self-driving rollout in China as chief Elon Musk meets…

13 hours ago

UK Law Aims To Boost Security For ‘Smart’ Devices

New UK rules bring in basic security requirements for millions of internet-connected devices, aiming to…

15 hours ago

Alphabet Value Surges Over $2tn On Dividend Plan

Google parent Alphabet sees market capitalisation surge over $2tn on plan to over first-ever cash…

21 hours ago

Google Asks US Court To Dismiss Federal Adtech Case

Google asks Virginia federal court to dismiss case brought by US Justice Department and eight…

21 hours ago

Snap Sees Surge In Users, Ad Revenues

Snapchat parent Snap reports user growth, revenues in spite of tough competition, in what may…

22 hours ago

Shein Subject To Most Stringent EU Digital Rules

Quick-growing fast-fashion company Shein must comply with most stringent level of EU digital rules after…

22 hours ago