Story image

State-sponsored North Korean cyberespionage group continues to weaponize tactics

21 Feb 18

The North Korean threat group known to some as Reaper (APT37) is eyeing bigger targets with more sophisticated tactics, and according to researchers from FireEye, the group may just be one of the world’s most overlooked threat actors connected to the North Korean government.

FireEye tracked a North Korean cyberespionage group behind an Adobe Flash exploit (CVE-2018-4878) earlier this month, which the team has now identified as Reaper.

“We assess with high confidence that this activity is carried out on behalf of the North Korean government given malware development artifacts and targeting that aligns with North Korean state interests. FireEye iSIGHT Intelligence believes that APT37 is aligned with the activity publicly reported as Scarcruft and Group123,” FireEye researchers state in a research report.

The group uses vulnerabilities in the popular software Hangul Word Processor due to its prevalence in South Korea, and zero-day vulnerabilities in Adobe Flash.

Since November 2017 Reaper has been exploiting the vulnerability to distribute DOGCALL malware to South Korean victims.

“Multiple South Korean websites were abused in strategic web compromises to deliver newer variants of KARAE and POORAIM malware. Identified sites included South Korean conservative media and a news site for North Korean refugees and defectors. In one instance, APT37 weaponized a video downloader application with KARAE malware that was indiscriminately distributed to South Korean victims through torrent websites,” the report says.

The group has been active since at least 2012 and has targeted many countries in Asia and the Middle East. It primarily targets South Korea – though also Japan, Vietnam and the Middle East – in various industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare.

Reaper has supposedly ramped up its scope and sophistication with tools that can access wiper malware and can also access zero-day vulnerabilities.

Reaper also uses spear phishing tactics, strategic web compromised and torrent file-sharing sites to distribute their malware.

According to FireEye, the group’s command and control infrastructure includes compromised servers, messaging platforms, and cloud service providers to avoid detection. The group has shown increasing sophistication by improving their operational security over time.

“APT37 has used various legitimate platforms as command and control for its malware tools. While some early campaigns leveraged POORAIM, which abused AOL Instant Messenger, newer activity deploys DOGCALL, which uses cloud storage APIs such as pCloud and Dropbox,” the report says.

FireEye researchers believe that Reaper will not disappear anytime soon, particularly as it now demonstrate a willingness to leverage its cyber capabilities for a variety of reasons. They also seem disinterested by international norms.

“We anticipate APT37 will be leveraged more and more in previously unfamiliar roles and regions, especially as pressure mounts on their sponsor.”

Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
Businesses too slow on attack detection – CrowdStrike
The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 cases.
What disaster recovery will look like in 2019
“With nearly half of all businesses experiencing an unrecoverable data event in the last three years, current backup solutions are no longer fit for purpose."
Proofpoint launches feature to identify most targeted users
“One of the largest security industry misconceptions is that most cyberattacks target top executives and management.”
McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
25% of malicious emails still make it through to recipients
Popular email security programmes may fail to detect as much as 25% of all emails with malicious or dangerous attachments, a study from Mimecast says.