Security News > 2021 > March > Google: North Korean hackers target security researchers again
Google's Threat Analysis Group says that North Korean government-sponsored hackers are once again targeting security researchers using fake Twitter and LinkedIn social media accounts.
The hackers also created a website for a fake company named SecuriElite and supposedly offering offensive security services as the Google security team focused on hunting down state-backed hackers discovered on March 17.
Just as in the attacks detected during January 2021, this site was also hosting the attackers' PGP public key, which was used as bait to infect security researchers with malware after triggering a browser exploit on opening the page.
In January, North Korean state hackers tracked as the Lazarus Group targeted security researchers in social engineering attacks using elaborate fake "Security researcher" social media personas.
Some researchers using fully patched Windows 10 computers and running the latest Google Chrome version were infected in the attacks, indicating that the hackers were using zero-day vulnerabilities to compromise the targets' devices.
An additional Internet Explorer zero-day was discovered by South Korean cybersecurity firm ENKI after failed attacks on their security researchers.
News URL
Related news
- North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks (source)
- Researchers Uncover 4-Month Cyberattack on U.S. Firm Linked to Chinese Hackers (source)
- Radiant links $50 million crypto heist to North Korean hackers (source)
- MUT-1244 targeting security researchers, red teamers, and threat actors (source)
- Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection (source)
- North Korean hackers stole $1.3 billion worth of crypto this year (source)
- North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin (source)
- FBI links North Korean hackers to $308 million crypto heist (source)
- North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign (source)
- New details reveal how hackers hijacked 35 Google Chrome extensions (source)