North Korean hackers launch "email attacks" ahead of US-South Korea drills
Seoul, South Korea - Suspected North Korean hackers have attempted an attack targeting a major joint military exercise between Seoul and Washington that starts on Monday, South Korean police said.
South Korea and the US will kick off the annual Ulchi Freedom Shield drills on Monday through August 31.
The hackers – believed to be linked to a North Korean group dubbed Kimsuky – carried out "continuous malicious email attacks" on South Korean contractors working at the allies' combined exercise war simulation center, the Gyeonggi Nambu Provincial Police Agency said in a statement on Sunday.
"Police investigation confirms that North Korean hacking group was responsible for the attack," it said in a statement, adding that military-related information was not stolen.
North Korean hacker group uses "spearphishing" to attack targets
A joint investigation by the police and the US military found that the IP address used in the latest attack matched one identified in a 2014 hack against South Korea's nuclear reactor operator blamed on the group, according to the statement.
The Kimsuky hackers use "spearphishing" tactics – sending malicious attachments embedded in emails – to steal information from victims.
According to findings by the US Cybersecurity and Infrastructure Security Agency in 2020, Kimsuky is "most likely tasked by the North Korean regime with a global intelligence gathering mission."
The group – believed to be active since 2012 – targets individuals and organizations in South Korea, Japan, and the US, focusing on foreign policy and national security issues related to the Korean peninsula, nuclear policy, and sanctions, it added.
Cover photo: 123RF/3dgenerator