Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV //

Malware

1/11/2018
11:45 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

McAfee: Attackers Targeting North Korean Dissidents, Journalists

A report from McAfee finds that a group of attackers is targeting North Korean dissidents, as well as some journalists, through social networks and a South Korean chat app called KakaoTalk.

A previously unknown group of attackers is targeting North Korean dissidents, as well as journalists, through a combination of social media and a popular South Korean chat app called Kakao Talk, according to a new report from McAfee.

In this case, the McAfee Mobile Research Team found that the attackers use social media platforms, such as Facebook, or the chat app to deliver Trojan malware to a user's mobile device, particularly Android.

Specifically the attack uses malicious APK files, which use a file format that installs software on the Android OS, according to the January 11 report.

The McAfee Inc. (NYSE: MFE) team dubbed this group "Sun Team," after some information in one of the files that were studied. It seems that Sun Team has only been active since 2016. Although there was one North Korean IP address associated with these malicious files, it's not clear who the group is working for at this time.

"However, WiFi was on so we cannot exclude the possibility that the IP address is private," according to McAfee.

In its conclusion, McAfee states:

This malware campaign is highly targeted, using social network services and KakaoTalk to directly approach targets and implant spyware. We cannot confirm who is behind this campaign, and the possible actor Sun Team is not related to any previously known cybercrime groups. The actors are familiar with South Korea and appear to want to spy on North Korean defectors, and on groups and individuals who help defectors.

In an analysis of the files, the McAfee researchers found that attackers used two different prongs to target people. The first is called "Blood Assistant," which is a healthcare app, and the other is called "Pray for North Korea," which is an English translation.

To hide itself from the person who downloaded it, the malware can pop a video onto the screen until it's done installing. The malware also checks to see if the smartphone or any other device is already infected. If not, it uses a phishing technique to try getting the user to turn on the accessibility settings to gain control.

After it's installed, the Trojan uses a number of different cloud services to upload data, as well as to receive commands.

Related posts:

— Scott Ferguson, Editor, Enterprise Cloud News. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/14/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 New Cybersecurity Vulnerabilities That Could Put Your Enterprise at Risk
In this Dark Reading Tech Digest, we look at the ways security researchers and ethical hackers find critical vulnerabilities and offer insights into how you can fix them before attackers can exploit them.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17475
PUBLISHED: 2020-08-14
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
CVE-2020-0255
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751. Notes: All CVE users should reference CVE-2020-10751 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-14353
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270. Notes: All CVE users should reference CVE-2017-18270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-17464
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-17473
PUBLISHED: 2020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.