North Korea backed hackers targeting security researchers, Google claims

26 January 2021, 12:34

Google
North Korean-backed hackers targeting security researchers, Google claims. Picture: PA

Attackers would lure security researchers into collaborating via social media and a fake blog.

Google has warned security researchers they are being targeted by an ongoing government-backed hacking campaign based in North Korea.

The tech giant said it uncovered several false social media profiles on platforms including Twitter and LinkedIn, where bad actors would lure targets to a fake blog featuring “guest” posts from unwitting legitimate security researchers.

According to Google’s Threat Analysis Group, attackers would then start talking to potential targets, asking if they would like to work together on cyber vulnerability research and use collaboration tools with hidden malware.

In several cases, this allowed perpetrators to install a backdoor on to victims’ computers, even if they were running up-to-date versions of Windows 10 and the Chrome web browser.

“Over the past several months, the Threat Analysis Group has identified an ongoing campaign targeting security researchers working on vulnerability research and development at different companies and organisations,” said Adam Weidemann, from Google’s Threat Analysis Group.

“We hope this post will remind those in the security research community that they are targets to government-backed attackers and should remain vigilant when engaging with individuals they have not previously interacted with.”

Examples of fake accounts used by hackers
Examples of fake accounts used by hackers (Google/PA)

It comes as North Korea was recently accused by Microsoft of attempting to hack data from pharmaceutical firms and coronavirus vaccine researchers.

In November, the company said that state-backed hackers run by Russia and North Korea had targeted people located in Canada, France, India, South Korea and the US who are “directly involved in researching vaccines and treatments for Covid-19”.

Stuart Reed, UK director of security provider Orange Cyberdefense, said: “This is another example of an attempt by highly sophisticated cyberthreat actors to attack the people that are trying to protect us.

“In the past year we have seen a growing number of such incidents – hackers using social engineering attacks, malware campaigns and a whole host of other tricks to disrupt, misinform, aggravate existing geopolitical tensions and generally spread harm.

“As a result, the emergent threat model has shifted, creating a new normal for cybersecurity professionals trying to temper panic and anxiety with logical, strategic thinking.”

By Press Association

More Technology News

See more More Technology News

A person holds an iphone showing the app for Google chrome search engine

Apple and Google ‘should face investigation over mobile browser duopoly’

UK unveils AI cyber defence lab to combat Russian threats, as minister pledges unwavering support for Ukraine

British spies to ramp up fight against Russian cyber threats with launch of cutting-edge AI research unit

Pat McFadden

UK spies to counter Russian cyber warfare threat with new AI security lab

Openreach van

Upgrade to Openreach ultrafast full fibre broadband ‘could deliver £66bn boost’

Laptop with a virus warning on the screen

Nato countries are in a ‘hidden cyber war’ with Russia, says Liz Kendall

Pat McFadden

Russia prepared to launch cyber attacks on UK, minister to warn

A Google icon on a smartphone

Firms can use AI to help offset Budget tax hikes, says Google UK boss

Icons of social media apps, including Facebook, Instagram, YouTube and WhatsApp, are displayed on a mobile phone screen

Growing social media app vows to shake up ‘toxic’ status quo

Will Guyatt questions who is responsible for the safety of children online

Are Zuckerberg and Musk responsible for looking after my kids online?

Social media apps on a phone

U16s social media ban punishes children for tech firm failures, charities say

Google shown on a smartphone

US Government proposes forcing Google to sell Chrome to break-up tech empire

The logo for Google's Gemini AI assistant

Google’s Gemini AI gets dedicated iPhone app in the UK for the first time

Facebook stock

EU fines Meta £660m for competition rule breaches over Facebook Marketplace

A phone taking a photo of a phone mast

Government pledges more digital inclusion as rural Wales gets phone mast boost

Social media apps displayed on a mobile phone screen

What is Bluesky and why are people leaving X to sign up?

Someone types at a keyboard

Cyber security chief warns Black Friday shoppers to be alert to scams