Tying together various threads uncovered by themselves and other security companies over the last few years, security researchers at FireEye have concluded that a series of attacks represent a discrete cyber-espionage group operating on behalf of North Korea.
FireEye named the group APT37 in a report released this week, "APT37 (Reaper): The Overlooked North Korean Actor." The report connects APT37 to other attacks dating back to 2014, including the recent zero-day vulnerability CVE-2018-4878 that was disclosed on Feb. 1. Successful exploitation of that Adobe Flash Player vulnerability could allow an attacker to take control of an affected system.
FireEye's report ties that vulnerability to activities reported by other researchers, including Kaspersky Lab, which identified a group of attackers as ScarCruft, and Cisco's Talos unit, which identified the activities of a Group 123. The FireEye report goes further in pinpointing the group's origin as North Korea.
"We assess with high confidence that this activity is carried out on behalf of the North Korean government given malware development artifacts and targeting that aligns with North Korean state interests," FireEye wrote in the introduction to the report.
"We judge that APT37's primary mission is covert intelligence gathering in support of North Korea's strategic military, political and economic interests. This is based on consistent targeting of South Korean public and private entities and social engineering. APT37's recently expanded targeting scope also appears to have direct relevance to North Korea's strategic interests."
What's interesting about the report is that FireEye views APT37 as separate from the internationally isolated country's main suspected cyber-espionage and operations unit, which researchers call Lazarus. According to FireEye, the capabilities of APT37 are increasing, the unit's international scope of operations is expanding, and the group is likely to become another tool in North Korea's global cyber-operations arsenal.
Posted by Scott Bekker on 02/21/2018 at 8:44 AM
Microsoft this week included some Windows 11 client news amid its many Build announcements for developers, promising to soon deliver new features to Windows 11 version 22H2 users.
Microsoft this week announced a few product additions to Microsoft Entra, which is Microsoft's branded suite of identity and access management solutions.
Microsoft this week described a bunch of Microsoft Edge browser enhancements as part of its Build developer event announcements.
Microsoft Mesh, the company's mixed reality communication and collaboration platform, will be hitting private preview this week.
"It does feel like every week, there is something new," said Microsoft CEO Satya Nadella on Tuesday, during the opening keynote of Build 2023.
More Tech Library