Shared Malware and Infrastructure Revealed in North Korean Cyber Activities
A recent investigation has unveiled alarming developments in North Korea’s cyber landscape, revealing a blend of espionage and criminal undertakings previously confined to state operations. In a significant report, South Korean cybersecurity firm AhnLab comprehensively documented a series of operations that demonstrate how the hacking capabilities once solely wielded by the North Korean government are now permeating private sectors. This evolution is exemplified in the activities of the Gunra ransomware gang, which shares noticeable parallels with state-sponsored hacking tactics, especially those employed by renowned organizations such as the Lazarus Group.
The AhnLab report describes an operation it has dubbed "Operation Double Barrel." During this investigation, the firm highlights distinct convergences in tactics, techniques, and procedures (TTPs) between the Gunra ransomware group and regimes’ cyber units. These parallels raise significant concerns regarding the relationships, if any, between these cybercriminals and the broader North Korean cyber operations.
AhnLab pointed out that insights from various campaigns indicate a dual narrative: while state-sponsored hacker groups focus on national goals, private entities such as Gunra seem to be taking illicit cyber techniques learned from these state-sponsored actors and utilizing them for personal gain. This troubling trend is illustrated by the exploits of ex-military personnel who have transitioned into rogue cyber operators, showing that hacking skills cultivated in service can easily be misused to compromise the state itself.
Supporting these conclusions, reports from the South Korean online newspaper Daily NK shed light on a particularly scandalous twist in this saga. Discharged veterans from North Korea’s military intelligence organization have been implicated in forming a criminal hacking ring, recruiting skilled individuals from universities to establish a sophisticated cryptocurrency-laundering network. This group allegedly infiltrated major North Korean banks, undermining the very state entities that had once trained them.
AhnLab’s document further elaborates that both Lazarus and Gunra utilized similar initial access vulnerabilities within South Korean financial security software. These vulnerabilities enabled both groups to launch attacks using shared malware and SSH keys and even common network infrastructure. Despite presenting themselves as distinct entities with differing objectives, these findings suggest a troubling collaboration or knowledge transfer between them during their respective operations.
In their detailed report, AhnLab reveals how the Lazarus Group targeted legitimate South Korean websites across various industries, including media, education, healthcare, and manufacturing. These sites were often frequented by individuals in high-profile positions, making them prime targets for compromise. The report indicates that Lazarus often employed phishing tactics, sending out emails disguised as resumes or surveys containing malicious links. Following this initial compromise, the group exploited outdated versions of Korean financial security software, eventually implanting backdoor malware.
On the other hand, while the Gunra ransomware group exploited similar vulnerabilities, their endgame was the deployment of ransomware designed to encrypt critical files and exfiltrate sensitive information from organizations. Employing a double-extortion model and utilizing ransomware-as-a-service tactics, Gunra has effectively pressured organizations into paying ransoms to recover their data.
The broader implications of these cyber campaigns reveal a nexus of organized crime and state-sponsored hacking, effectively blurring the lines that once defined these operations. As reported by Daily NK, the saga reached a climax when a criminal ring of ex-government hackers succeeded in siphoning "substantial wealth" from state trade funds. Utilizing technical skills learned during their military service, these individuals breached the internal networks of North Korea’s Chosun Central Bank and the Foreign Trade Bank, employing sophisticated methods involving foreign technology to facilitate their illegal activities. This theft involved meticulously breaking down large sums into smaller transactions to launder through cryptocurrency wallets abroad.
Despite substantial efforts to evade detection, authorities eventually spotted discrepancies in accounting and suspicious IP traffic, leading to the arrests of several key figures in a raid on July 12. According to sources in Pyongyang, officials expressed concerns over the implications of such betrayals, stating, "They used the skills the state trained them with to defend the country, and instead robbed the country’s coffers." This betrayal highlights a concerning reality: the very individuals trained to protect national interests have turned their skills against the state.
In conclusion, the convergence of North Korean state-sponsored hacking techniques and the criminal acts of groups like Gunra represents a significant shift in the cyber realm. This troubling development not only poses security challenges for North Korea but also raises profound questions about the stability of its cyber operations, where former government operatives now exploit their training for personal gain, undermining the state’s authority and resources. As these dynamics evolve, cybersecurity experts will need to remain vigilant in monitoring and understanding the implications of this dangerous confluence of motive and capability.
