Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

6/5/2018
11:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

North Korean-Linked Group Stops Targeting US Ahead of Summit

Covellite, which has been linked to North Korea, has stopped targeting facilities in the US and other parts of North America ahead of a planned summit later this month.

President Trump's nuclear diplomacy with North Korea may have yielded an unexpected benefit for North America: reduced cyberattacks from at least one group associate with the North Korean regime.

Covellite, a group associated with attacks on electrical and other critical facilities, as well the theft of intellectual property, has ceased its activity in North America after being active since at least the middle of 2017, according to Dragos, a company that specializes in industrial control system (ICS) security.

This cyberespionage group has also targeted facilities in Asia and Europe.

Dragos has observed Covellite use phishing emails that contain malicious Microsoft Word documents, typically ones that look similar to resumes or invitations, to deliver malware and infect systems. These documents contain remote access tools (RATs), and once the payload is delivered, the malware allows the group to conduct industrial espionage and gain access to other parts of the network.

Now, however, the group's activities seem to be on hold, especially in North America, according to Dragos:

COVELLITE remains active but appears to have abandoned North American targets, with indications of activity in Europe and East Asia. Given the group's specific interest in infrastructure operations, rapidly improving capabilities, and history of aggressive targeting, Dragos considers this group a primary threat to the ICS industry.

In their May 31 report, Dragos researchers note that Covellite's malware and infrastructure is similar to another North Korean-backed group, which is alternatively called the Lazarus Group by some, and Hidden Cobra by others.


Now entering its fifth year, the 2020 Vision Executive Summit is an exclusive meeting of global CSP executives focused on navigating the disruptive forces at work in telecom today. Join us in Lisbon on December 4-6 to meet with fellow experts as we define the future of next-gen communications and how to make it profitable.

Lazarus or Hidden Cobra is the group that is behind several of the biggest malicious hacks, including the one that targeted Sony Pictures four years ago. (See Cybercrime Is North Korea's Biggest Threat.)

While Covellite and Lazarus do share some technical similarities, it's not clear if the two groups work in conjunction. In fact, despite the fact that Covellite has backed away from attacking US targets, the FBI and US Department of Homeland Security issued a joint warning last week about two different strains of malware stemming from the Hidden Cobra group that is targeting industries including media, aerospace and finance as well a critical infrastructure. (See FBI & DHS Warn About 2 North Korea Malware Threats .)

Maybe not every cyberespionage group got the memo that the US and North Korea summit is still scheduled for June 12.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
4 Security Tips as the July 15 Tax-Day Extension Draws Near
Shane Buckley, President & Chief Operating Officer, Gigamon,  7/10/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...