Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Cyber-Attacks From North Korea Jump Significantly: Solutionary

Researchers at Solutionary say attack activity originated from North Korea has jumped exponentially in recent months.

Researchers at Solutionary say attack activity originated from North Korea has jumped exponentially in recent months.

According to Solutionary, North Korea typically generates between 34 and 200 “touches” – known acts of reconnaissance, an overt external attack or an attempt to exfiltrate data – each month. In February however, that number increased several times over to 12,473.

“What is special about February of 2013? Only the latest escalation of events with North Korea,” blogged Jon Heimerl, director of strategic security at Solutionary. “On February 12, North Korea announced that it had conducted an underground nuclear test. While there is some debate over whether or not the detonation was nuclear, an underground explosion consistent with a nuclear warhead has been confirmed by several other nations. The test generated widespread condemnation and once again raised potential sanctions against North Korea. North Korea has responded with additional aggressive words, and another threat to test one of their missiles that they say is capable of delivering a nuclear warhead.”

The sheer size of the increase indicates that this is not a coincidence, he argued. In addition, the numbers in March represented a 1,913 percent increase compared to the average number of monthly touches recorded during the January 2012 and January 2013 timeframe, he wrote.

“Just as interesting is the profile of the targets of the network-based touches,” he noted. “According to Solutionary data, North Korean related events pretty evenly spanned target organizations across 13 industries, but showed a clear favoritism for targeting organizations in the financial community.”

From January 2012 through January 2013, 49.1 percent of all North Korean sourced cyber-activity seen by Solutionary was directed at financial companies. In February however, that number jumped to 99 percent. This trend continued into March and spanned the same timeframe that North Korea waged denial of service attacks against South Korean banks and broadcasting companies, he wrote.

“Now, there is no evidence that any of this is supported or even encouraged by the North Korean government,” blogged Heimerl. “But, there do appear to be several parallels between escalated verbal rhetoric and escalated cyberattacks. It is evident that, whether government influenced or not, that the dual-path of aggression is a new way of facing the world, at least from North Korea. Given the more hard-line government in North Korea, we expect escalations like this to continue, and to become even more evident in other conflicts around the globe.” 

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...