North Korean hackers target security researchers with fake social media accounts

Cyber spies also set up fake Turkish security website to entice victims

North Korean hackers that targeted security researchers back in January have returned in a new attack using fake Twitter and LinkedIn social media accounts.

According to researchers at Google's Threat Analysis Group (TAG), the hackers set up a new website with associated social media profiles for a fake company called “SecuriElite” on March 17.

This fake website claimed it was “an offensive security company located in Turkey that offers pentests, software security assessments and exploits”.

The website had a link to the hackers’ PGP public key at the bottom of the page. Earlier this year, researchers reported that the PGP key hosted on the attacker’s blog acted as the lure to visit the site where a browser exploit was waiting to be triggered.

Google researchers said they hadn’t seen this new fake website serving malicious content but have added it to Google Safebrowsing as a precaution.

The hackers set up several social media accounts to pose as fellow security researchers interested in exploitation and offensive security. Researchers said that on LinkedIn, two accounts were identified as impersonating recruiters for antivirus and security companies. Since then, these profiles have been reported to the relevant social media companies to take appropriate action.

Google’s Threat Analysis Group's Adam Weidemann said his team believes that these actors are dangerous and likely have more zero-days based on their activity.

"We encourage anyone who discovers a Chrome vulnerability to report that activity through the Chrome Vulnerabilities Rewards Program submission process,” he added.

In January, Google’s Threat Analysis Group identified an ongoing campaign targeting security researchers working on vulnerability research and development at different companies and organizations. This campaign was run by the Lazarus APT group closely linked to the North Korean regime. 

In this previous attack, hackers set up a research blog and multiple Twitter profiles to interact with potential targets to build credibility and connect with security researchers. These hackers used Twitter profiles to post links to their blog and videos of their claimed exploits, and amplify and retweet posts from other accounts they controlled.

As reported by ITPro, the Lazarus APT group has also used spear-phishing attacks targeting defense industry companies. Victims received emails with malicious Word attachments or links to them hosted on company servers. Malware in these emails gave hackers full control of the victim’s device.

Featured Resources

Next-generation time series: Forecasting for the real world, not the ideal world

Solve time series problems with AI

Free download

The future of productivity

Driving your business forward with Microsoft Office 365

Free download

How to plan for endpoint security against ever-evolving cyber threats

Safeguard your devices, data, and reputation

Free download

A quantitative comparison of UPS monitoring and servicing approaches across edge environments

Effective UPS fleet management

Free download

Recommended

BillQuick billing software exploit lets hackers deploy ransomware
Security

BillQuick billing software exploit lets hackers deploy ransomware

26 Oct 2021
Ransomware hit industrial sector the hardest in the third quarter
ransomware

Ransomware hit industrial sector the hardest in the third quarter

25 Oct 2021
Tesco services knocked offline after suspected cyber attack
hacking

Tesco services knocked offline after suspected cyber attack

25 Oct 2021
Microsoft touts new cyber security help for nonprofits
cyber security

Microsoft touts new cyber security help for nonprofits

22 Oct 2021

Most Popular

Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans
Laptops

Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans

11 Oct 2021
PayPal dismisses $45 billion Pinterest takeover as "market rumour"
Acquisition

PayPal dismisses $45 billion Pinterest takeover as "market rumour"

25 Oct 2021