North Korea-backed cyber group sought to steal nuclear secrets, NCSC says

25 July 2024, 17:34

The NCSC said the Andariel group has been compromising organisations around the world (PA)
NHS cyber attacks. Picture: PA

The National Cyber Security Centre said it showed how far Pyongyang was willing to go to pursue its military and nuclear programmes.

A North Korea-backed cyber group has been accused by the UK, US and South Korea of carrying out an online espionage campaign to steal military and nuclear secrets.

The National Cyber Security Centre (NCSC) said the Andariel group has been compromising organisations around the world to steal sensitive and classified technical information and intellectual property data.

NCSC director of operations Paul Chichester said: “The global cyber espionage operation that we have exposed today shows the lengths that DPRK (Democratic People’s Republic of Korea) state-sponsored actors are willing to go to pursue their military and nuclear programmes.”

The NCSC believes that Andariel is a part of DPRK’s reconnaissance general bureau (RGB) 3rd bureau, and the group’s malicious cyber activities pose an ongoing threat to critical infrastructure organisations globally.

Andariel primarily targeted defence, aerospace, nuclear and engineering organisations, but also acted against the medical and energy sectors.

The group has attempted to obtain information such as contract specification, design drawings and project details.

It also launched ransomware attacks against US healthcare organisations in order to extort payments and fund further espionage activity, the NCSC said.

The NCSC, part of the GCHQ intelligence agency, issued the joint warning and advisory note about Andariel’s actions with organisations including the US Federal Bureau of Investigation and South Korea’s national intelligence service.

Mr Chichester said: “It should remind critical infrastructure operators of the importance of protecting the sensitive information and intellectual property they hold on their systems to prevent theft and misuse.

“The NCSC, alongside our US and Korean partners, strongly encourage network defenders to follow the guidance set out in this advisory to ensure they have strong protections in place to prevent this malicious activity.”

The advisory outlines how Andariel has evolved from destructive hacks against US and South Korea organisations to carrying out specialised cyber espionage and ransomware attacks.

In some cases, the hackers carried out both ransomware attacks and cyber espionage operations on the same day against the same victim.

The US State Department offered a reward of up to 10 million US dollars (£7.76 million) for information on Rim Jong Hyok, who it said was associated with Andariel.

The department said Rim and others conspired to carry out ransomware attacks on US hospitals and other healthcare providers to fund its operations against government bodies and defence firms.

US law enforcement agencies believe Andariel targeted five healthcare providers, four US-based defence contractors, two US Air Force bases and Nasa’s office of inspector general.

In one operation that began in November 2022, the hackers accessed a US defence contractor from which they extracted more than 30 gigabytes of data, including unclassified technical information regarding material used in military aircraft and satellites.

By Press Association

More Technology News

See more More Technology News

CES 2025 signage

CES ‘doesn’t have the same support’ from the UK as other nations, show boss says

The firm said it would begin a pilot of the new system with a L'Oreal brand in stores in Asia later in 2025. (L'Oreal)

New L’Oreal skin analysis tool can help predict aging and cosmetic issues

Samsung's Vision AI smart assistant, which are built into Samsung's TVs to act as a virtual assistant

Samsung unveils plans to turn TVs into AI assistants

Signage and staging at the CES show in Las Vegas

AI, car tech and ‘weird’ gadgets expected to dominate at CES trade show

Sir Nick Clegg

Clegg leaves Meta role as Republican promoted ahead of Trump presidency

A Polestar 4 electric car

Does the Polestar 4 offer a glimpse of the cars of the future?

The Duchess of Sussex

Meghan returns to Instagram with beach video

The app intervenes when smoking is detected (University of Bristol/PA)

Smartwatch technology could help people quit smoking, study finds

Elon Musk

Downing Street rejects Musk’s suggestion companies are turning away from UK

A person using their phone at a pedestrian crossing

Predicting the future in 1999: Tech predictions 25 years on

Manny Wallace, known as Big Manny on TikTok, smiling and standing inside a science lab

TikToker teaching science hopes short-form video will become part of curriculum

An information screen in the South Terminal at Gatwick Airport (PA)

How the CrowdStrike outage made IT supply chains the new big issue in tech

The Airbnb app icon

Airbnb activates ‘defences’ to stop unauthorised New Year parties

Artificial Intelligence futuristic light sign

Regulations needed to stop AI being used for ‘bad things’ – Geoffrey Hinton

Elon Musk

How Elon Musk’s influence has grown both online and offline in 2024

Hands holding the iPhone 16

How smartphones powered the AI boom in 2024