Illustration = ChatGPT DALL·E 3/Courtesy of ChatGPT

As phishing emails disguised as support or donation offers and "watering hole" attacks exploiting news and hospital websites have continued, the government and the private security industry issued a joint warning. The security industry suspects that a series of attacks detected several times in the first half of the year were carried out by the North Korea-backed hacking group "Lazarus."

According to the security industry on the 30th, the National Intelligence Service (NIS), the Korean National Police Agency, the Korea Internet & Security Agency (KISA), and the Financial Security Institute shared a recent "joint cyber security advisory" with private security corporations including AhnLab, S2W, ENKI WhiteHat, and Plainbit.

The hacking group mainly sends emails disguised with content likely to draw recipients' interest, such as job applications or donation offers. A tactic was also confirmed in which a resume is inserted in the email body as an internet L.I.N.C rather than as an attached file.

When the L.I.N.C is clicked, it leads to webpages such as blogs or GitHub that the hacking group directly set up or hijacked. In this process, vulnerabilities in outdated security programs installed on the PC can be exploited, allowing infection with malware even without running a separate file.

They also use a method of sending malicious attachments directly. They disguise them as recruitment offers like "high-paying job offer" to induce recipients to open the attachments. There were also cases detected in which an actual headhunter's email account was hijacked to make the message appear to come from a legitimate sender.

They also use watering hole attacks, in which websites that users visit frequently, such as news outlets or hospitals, are hacked in advance and seeded with malware. When a user accesses the tampered site, malware is automatically installed through vulnerabilities in security programs installed on the PC.

The advisory said recent watering hole tactics are becoming more sophisticated by hiding malware or directly tampering with website source code, making detection through security monitoring more difficult. If security software such as electronic signature, security authentication, or keyboard security programs are not the latest versions, the risk of infection can increase.

The security industry believes these attacks are similar to the methods of Lazarus, which targeted domestic users and corporations several times in the first half of the year.

If infected with malware, everything from accounts, passwords, and card numbers stored in the browser to documents, photos, contacts on the PC, and messenger chat contents can be leaked. The malware can also spread in a chain to nearby PCs on the same network by using the infected PC as a foothold.

For corporations, there is a need for particular caution, as source code, internal documents, customer and HR information, and trade secrets can be stolen and then used to extort money.

The advisory recommended that individual users update all software to the latest versions, enable two-step verification on important accounts, and not open email attachments and L.I.N.Cs from unknown sources.

※ This article has been translated by AI. Share your feedback here.