CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

US Offers $10 Million Reward for Information on North Korean Hacker

The US is offering a reward of up to $10 million for information on Rim Jong Hyok, a member of the North Korean hacking group APT45.

North Korean hacking

The US Department of State has announced a reward of up to $10 million for information on a North Korean national charged with hacking hospitals, military bases, and NASA.

The individual, Rim Jong Hyok, is an alleged member of the hacking group tracked as APT45, Andariel, DarkSeoul, Onyx Sleet (formerly Plutonium), Silent Chollima, and Stonefly/Clasiopa, which operates on behalf of a North Korean military intelligence agency, the Reconnaissance General Bureau.

The group, the US says, has been targeting foreign businesses, government entities, and the defense industry for cyberespionage and financial gain.

Rim was charged in a US court this week for his alleged role in the hacking of American healthcare organizations, NASA, and military bases, along with international entities and for laundering the illicit proceeds.

“Rim and others conspired to hack into the computer systems of U.S. hospitals and other healthcare providers, install Maui ransomware, and extort ransoms,” the Department of State said.

The illegally obtained funds, the US says, were then used to fuel North Korea’s cyber operations, which in turn fund the country’s arms race.

Advertisement. Scroll to continue reading.

In one intrusion, which started in November 2022 and targeted a US-based defense contractor, the threat actors stole more than 30 gigabytes of data, including technical information on older military aircraft and satellite material.

Andariel hacked five healthcare providers, four defense contractors in the US, two Air Force bases, and NASA’s Office of Inspector General, the US says.

“We encourage anyone with information on the malicious cyber activity of Rim Jong Hyok, Andariel, and associated individuals, entities, and activities to contact Rewards for Justice via the Tor-based tips-reporting channel,” the Department of State noted.

The $10 million reward was announced on the same day that Mandiant published a detailed report on the threat actor’s activities. The Google Cloud-owned cybersecurity firm now tracks the hacking group as APT45.

On Thursday, government agencies in the US, Korea, and the UK published a joint advisory on the advanced persistent threat (APT) actor, sharing information on its malware, tactics, and victimology. Microsoft too published a blog post sharing its insights into the group’s activities.

Related: KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware 

Related: New North Korean Threat Actor Engaging in Espionage, Revenue Generation Attacks

Related: Woman Accused of Helping North Korean IT Workers Infiltrate Hundreds of US Firms

Related: US Says North Korean Hackers Exploiting Weak DMARC Settings

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.