Anzeige
Mehr »
Login
Donnerstag, 02.05.2024 Börsentäglich über 12.000 News von 685 internationalen Medien
"Special Situation"-Aktie mit Multi-Tenbagger-Potenzial im heißesten Rohstoff-Markt
Anzeige

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
PR Newswire
360 Leser
Artikel bewerten:
(1)

DPRK-aligned threat actor targeting cryptocurrency vertical with global hacking campaign

F-Secure connects attack on organization working in the cryptocurrency vertical with a global Lazarus Group campaign, in spite of attacker's efforts to destroy evidence

HELSINKI, Aug. 25, 2020 /PRNewswire/ -- Today, cyber security provider F-Secure published a report linking an attack against an organization working in the cryptocurrency vertical to Lazarus Group - a highly-skilled, financially-motivated threat actor whose interests reportedly align with the Democratic People's Republic of Korea (DPRK). By connecting evidence obtained from the attack with existing research, the report concludes the incident was part of a Lazarus Group campaign targeting organizations in the cryptocurrency vertical in the United States, the United Kingdom, the Netherlands, Germany, Singapore, Japan, and other countries.

The tactical intelligence report provides an analysis of samples, logs, and other technical artifacts recovered by F-Secure during an incident response investigation at an organization working in the cryptocurrency vertical. According to the report, the malicious implants used in the attack were nearly identical to tools reportedly used previously by Lazarus Group - also known as APT38.

The report identifies the Tactics, Techniques, and Procedures (TTPs) used during the attack, such as spearphishing via a service (in this case, using LinkedIn to send a fake job offer tailored to the recipient's profile). According to F-Secure Director of Detection and Response Matt Lawrence, the research provides a solid foundation for the report's actionable security advice.

"Our research, which included insights from our incident response, managed detection and response, and tactical defense units, found that this attack bears a number of similarities with known Lazarus Group activity, so we're confident they were behind the incident," said Lawrence. "The evidence also suggests this is part of an ongoing campaign targeting organizations in over a dozen countries, which makes the attribution important. Companies can use the report to familiarize themselves with this incident, the TTPs, and Lazarus Group in general, to help protect themselves from future attacks."

Based on phishing artifacts recovered from Lazarus Group's attack, F-Secure's researchers were able to link the incident to a wider, ongoing campaign that's been running since at least January 2018. According to the report, similar artifacts have been used in campaigns in at least 14 countries: the United States, China, the United Kingdom, Canada, Germany, Russia, South Korea, Argentina, Singapore, Hong Kong, Netherlands, Estonia, Japan, and the Philippines.

Lazarus Group invested significant effort to evade the target organization's defenses during the attack, such as by disabling anti-virus software on the compromised hosts, and removing evidence of their malicious implants. And while the report describes the attack as sophisticated, it points out Lazarus Group's efforts to hide their presence were not enough to prevent F-Secure's investigation from recovering evidence of their activities.

The report, Lazarus Group Campaign Targeting the Cryptocurrency Vertical, contains more information for defenders, including indicators of compromise, a list of TTPs used in the attack, and additional advice for detecting Lazarus Group activity. It is now available on F-Secure Labs.

About F-Secure

Nobody has better visibility into real-life cyber attacks than F-Secure. We're closing the gap between detection and response, utilizing the unmatched threat intelligence of hundreds of our industry's best technical consultants, millions of devices running our award-winning software, and ceaseless innovations in artificial intelligence. Top banks, airlines, and enterprises trust our commitment to beating the world's most potent threats. Together with our network of the top channel partners and over 200 service providers, we're on a mission to make sure everyone has the enterprise-grade cyber security we all need.

Founded in 1988, F-Secure is listed on the NASDAQ OMX Helsinki Ltd.

f-secure.com | twitter.com/fsecure | linkedin.com/f-secure

F-Secure media relations
Sandra Proske
+49 176 700 36664

This information was brought to you by Cision http://news.cision.com

Kupfer - Jetzt! So gelingt der Einstieg in den Rohstoff-Trend!
In diesem kostenfreien Report schaut sich Carsten Stork den Kupfer-Trend im Detail an und gibt konkrete Produkte zum Einstieg an die Hand.
Hier klicken
© 2020 PR Newswire
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.