A new report by McAfee Advanced Threat Research found a major hacking campaign, dubbed Operation GhostSecret, sought to steal sensitive data from a wide range of industries including critical infrastructure, entertainment, finance, healthcare, and telecommunications.
Attackers used tools and malware programs associated with the North Korea-sponsored cyber unit Hidden Cobra, also known as Lazarus, to execute the highly sophisticated operation.
Operation GhostSecret is thought to have started with a massive cyberattack on several Turkish financial institutions and government organizations in early March. The cyberoffensive then began targeting industries in 17 countries and is still active, according to McAfee.
Servers in the US, Australia, Japan, and China were infected several times from March 15 to 19. Nearly 50 servers in Thailand were hit heavily by the malware, the most of any country.
McAfee researchers noted many similarities between the methods used in Operation GhostSecret and other major attacks attributed to the group, including the 2014 attack on Sony Pictures and last year's global WannaCry attack.
"As we monitor this campaign, it is clear that the publicity associated with the (we assume) first phase of this campaign did nothing to slow the attacks. The threat actors not only continued but also increased the scope of the attack, both in types of targets and in the tools they used," Raj Samani, McAfee's chief scientist, said.
The report indicates North Korea has been expanding its cybercrime beyond its usual focus of stealing military intel or cryptocurrency that can be used to funnel money to the heavily sanctioned government.
North Korean groups have been tied to increasingly high-stakes attacks in recent months.
In January, researchers from the US cybersecurity firm Recorded Future said a hacking campaign targeting the South Korean cryptocurrency exchange Coinlink employed the same malware used in the Sony and WannaCry attacks.
The attack was attributed to the Lazarus group, which has been conducting operations since at least 2009, when it launched an attack on US and South Korean websites by infecting them with a virus known as MyDoom.
You guys have surpassed my expectations! James is seriously amazing and is doing everything to help my Fiancé and me, in1weeks my credit score went up 700 points and I can only imagine what is to come. Thank you for the excellent customer service and doing exactly what you all have set out to do! NO GIMMICKS OR BS with you guys.They carry out any kind of hacks You can reachout to them via Hackintechnology@gmail.com +16692252253
ReplyDeleteYou guys have surpassed my expectations! James is seriously amazing and is doing everything to help my Fiancé and me, in1weeks my credit score went up 700 points and I can only imagine what is to come. Thank you for the excellent customer service and doing exactly what you all have set out to do! NO GIMMICKS OR BS with you guys.They carry out any kind of hacks You can reachout to them via Hackintechnology@gmail.com +16692252253
ReplyDelete