N. Korea Is Ready For Global Cyber Conflict

It’s no secret that North Korea has a cyber army working in the shadows to attack western interests. The cyber-attack against Sony Pictures in 2014 made it clear that the nation had developed its cyber warfare capabilities much more than had been realised until then.

But now it appears that North Korea has set its sights on loftier goals, perhaps spreading chaos and even damage worldwide through a well-placed series of cyber-attacks on defense targets, industry and media.

Now, US-CERT and the Federal Bureau of Investigation have issued a series of warnings intended to provide the necessary information for organisations to prevent or reduce the likelihood of a successful North Korean infiltration. However, it the warning may be too late for some organisation because their networks have been infected by the components of Hidden Cobra, which refers to the collection of malware being used to attack targets in South Korea and elsewhere around the world.

Hidden Cobra is an umbrella operation that launches malware against a wide variety of targets that North Korea is studying, apparently for future action. 

According to Paul Innella, CEO of TDI Security, the goal of the Hidden Cobra operation appears to have changed. He said that North Korea has moved from running ransomware operations to something more sinister, information gathering.
“A lot of it is polling information on network infrastructure data,” Innella explained. “They’re trying to map out what we have.” He said that this operation already resulted in a breach that compromised planning between the military of South Korea and the United States.

Innella said that there’s been discussion recently about recent failures of North Korean rocket launches and whether those failures occurred as a result of cyber-attacks by the west. He said that it appears that the North Korean effort to map out the infrastructure of organisations in the West is a precursor to cyber-war.

Initially the attacks are likely to be against the military or launch systems, Innella said. But the plans of the North Koreans apparently go beyond that. The warnings from the Department of Homeland Security through US-CERT and the FBI indicate that there are also plans to attack the financial sector, aerospace and telecommunications using its FallChill malware, which is part of Hidden Cobra.

FallChill is a remote administration tool that evades detection by encrypting its communications traffic using TLS (transport layer security). The malware is able to use its remote administration capabilities to map out a network and then to report what it finds. The idea is that once FallChill has mapped out the networks (including the defenses) North Korea will know what and where to attack for best effect.

Fortunately, there is something that can be done about Hidden Cobra and its components. Innella pointed out that while North Korea and its cyber forces are persistent, they’re not unbeatable. 
“On the scale of global cyber warfare, I wouldn’t say they’re the most impressive adversary,” Innella said. He added that they’re not the equal of China or Russia in terms of their ability to wage cyber-war.
While Innella said that North Korea is a very big cyber-threat, most CISOs should be able to prevent them from exploiting their networks.
“There’s nothing significantly different about their attacks,” Innella said. “Any robust defense program is going to have some level of threat awareness. Your CISO you would have already seen the CERT notice and made the changes.”
The recommendations by US-CERT provides enough information to enable your network security team to perform the necessary white listing, and should also be able to see from their routers and firewalls whether any traffic from FallChill or its Trojan companion, Volgmer, has passed in or out of your network. 

The alerts include the IP addresses that the malware uses for reporting and for command and control, enabling your IT security specialists to block those addresses.

The US-CERT note also makes specific recommendations that are important for keeping the North Korean malware at bay. 
They include application whitelisting, so that you can prevent anything from running on your servers except specific software, keeping operating systems up to date, keeping your antivirus and anti-malware software up to date and by restricting permissions to the level that is required for people to do their jobs and nothing more.
In addition, the recommendations include making sure your staff knows not to click on unknown links and not to go to suspicious websites. Innella said that most of the infections he’s seeing started with visits to dubious sites where a user did something dumb, such as clicking on a link that downloaded malware.

US-CERT also urged organisation to train all staff to recognise and avoid email scams. 

Good system hygiene is critical, and most of the steps for avoiding it are the same whether the threat is from North Korea or a cyber-criminal trying to get rich on ransomware. The US-CERT note also makes specific recommendations that are important for keeping the North Korean malware at bay. They include application whitelisting, so that you can prevent anything from running on your servers except specific software, keeping operating systems up to date, keeping your antivirus and anti-malware software up to date and by restricting permissions to the level that is required for people to do their jobs and nothing more.

In addition, the recommendations include making sure your staff knows not to click on unknown links and not to go to suspicious websites. Innella said that most of the infections he’s seeing started with visits to dubious sites where a user did something dumb, such as clicking on a link that downloaded malware. 

US-CERT also urged organisation to train all staff to recognise and avoid email scams, and that you not enable to macros in email software. Perhaps the thought of Kim Jung  Un leafing through your intellectual property files is enough to drive home the idea. You know the things you have to do to be safe, but for them to work, you have to actually do them.

Ein News

You Might Also Read:

US Data Systems Under Attack:

Microsoft Chief Says N. Korea Was Behind 'WannaCry:

 

« Startups Are Changing The Future Of Cybersecurity
Apple Must Fix Its Embarrassing Password Bug »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Egress Software Technologies

Egress Software Technologies

Egress Software Technologies is a leading provider of data security services designed to protect shared information throughout its lifecycle.

Nordic IT Security

Nordic IT Security

Nordic IT Security is a cyber security business forum in Scandinavia bringing together the converging worlds of IT, Cyber and Information Security.

Australian Information Security Association (AISA)

Australian Information Security Association (AISA)

AISA champions the development of a robust information security sector by building professional capacity and advancing the cyber security of the public, business and governments in Australia.

Zertificon Solutions

Zertificon Solutions

Zertificon is a leader in professional email encryption and data security.

MerlinCryption

MerlinCryption

MerlinCryption develops infrastructure security software, delivering advanced encryption, authentication, and random data generators, for Cloud, VoIP, eCommerce, M2M, and USB hardware.

OneVisage

OneVisage

Our award-winning 3DAuth digital identity platform turns any consumer mobile device into a real-time 3D facial scanner that securely authenticates the user in seconds.

CI-CERT

CI-CERT

CI-CERT is the national Computer Incident Response Team for Cote d'Ivoire.

Innovation Cybersecurity Ecosystem at BLOCK71 (ICE71)

Innovation Cybersecurity Ecosystem at BLOCK71 (ICE71)

Innovation Cybersecurity Ecosystem at BLOCK71 (ICE71) is Singapore's first cybersecurity entrepreneur hub.

GroupSense

GroupSense

GroupSense helps governments and enterprises take control of digital risk with cyber reconnaissance, counterintelligence and monitoring for breached credentials.

Edureka

Edureka

Edureka is an online technology training provider with the most effective learning system in the world. We help professionals learn trending technologies for career growth.

Accolite Digital

Accolite Digital

Accolite is an innovative, design thinking software company that guarantees seamless digital experiences with maximum results.

Secure Diversity

Secure Diversity

Secure Diversity is an innovative non-profit organization with leaders that think out of the box to create strategies & solutions to increase diversity in the cybersecurity industry.

HiSolutions

HiSolutions

HiSolutions is a renowned consulting firms for IT governance, risk & compliance in Germany, combining highly specialized know-how in the field with profound process competence.

People Driven Technology

People Driven Technology

People Driven Technology is a customer-obsessed organization. We leverage our decades of business, technology, and engineering experience to deliver outcomes for our clients.

Secfix

Secfix

Secfix helps companies get secure and compliant in weeks instead of months. We are on a mission to automate security and compliance for small and medium-sized businesses.

TrustMe

TrustMe

TrustMe’s integrated platform for business trust and resilience keeps organizations safe, secure, and trustworthy.