Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. Web
  5. News

U.S. claims North Korea has been silently infiltrating networks since 2009

Add as a preferred source on Google

The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) claim North Korea is silently infiltrating the media, aerospace, financial, and critical infrastructure sectors both in and out of the United States using two known families of malware. They believe the attack has been underway since at least 2009 and conducted by a state-sponsored hacker group dubbed as Hidden Cobra. 

In a joint Technical Alert issued on Wednesday, the DHL and FBI claim that Hidden Cobra is using two pieces of malware in its campaign: a remote access tool called Joanap and a Server Message Block (SMB) worm named Brambul. The goal is to infiltrate networks, maintain a presence undetected, and send all collected information back to the hacker group. 

Recommended Videos

“FBI has high confidence that Hidden Cobra actors are using the IP addresses — listed in this report’s IOC files — to maintain a presence on victims’ networks and enable network exploitation. DHS and FBI are distributing these IP addresses and other IOCs to enable network defense and reduce exposure to any North Korean government malicious cyber activity,” the report states. 

Joanap is typically the payload of another malware obtained through a compromised website or a malicious email attachment. It can establish a peer-to-peer network to create a botnet and accept commands from the hacker group. 

Outside the botnet aspect, Joanap is capable of file management on a compromised Windows device, process management, the creation and deletion of directories, and node management. The Technical Alert says once Joanap infects a PC, it creates a file to capture and store information such as the host IP address, the hostname, and the current system time. 

According to the report, an analysis of the infrastructure used by Joanup identified 87 compromised network nodes in 17 countries including Brazil, China, Egypt, Iran, Saudi Arabia, Sweden, and Taiwan.  

Meanwhile, Brambul is a worm serving as a “dropper” malware payload obtained by compromised sites and infected files. Once executed, it will scan the local network for additional PCs and attempt to gain unauthorized access through the file-sharing feature built into Windows. This is done through brute-force password attacks using a list of embedded passwords. 

If successful, Brambul will contact Hidden Cobra and relay the IP address, hostname, username, and password of each infiltrated PC. The hacker group can then remotely access the compromised PCs via the Windows file-sharing protocol (SMB) to harvest information, infect other PCs on the network, and more. 

While both malware can be troublesome for the mainstream web surfer, they could devastate corporations by obtaining proprietary and/or sensitive information, disrupting regular operations, and harm their reputation. The financial losses due to eradicating the malware can be costly as well. 

“DHS and FBI recommend that network administrators review the information provided, identify whether any of the provided IP addresses fall within their organizations’ allocated IP address space, and—if found—take necessary measures to remove the malware,” the report states. 

A downloadable copy of the indicators of compromise are available in CSV and STIX formats.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Firefox just made work and personal browsing easier to separate
Containers are now built into Firefox to keep work and personal accounts separate
mozilla-firefox

Mozilla has released Firefox 153, giving people a built-in way to keep work, personal, shopping, and banking activity apart. The update began rolling out to Release channel users on July 21 and also introduces HDR video playback on Windows, PDF improvements, and tighter controls over local files and network devices.

Containers open tabs in isolated spaces where cookies, logins, and site storage are not shared. Someone can remain signed into two accounts on the same website, keep a work Google account away from personal YouTube activity, or stop shopping cookies from following everyday browsing.

Read more
ChatGPT can now connect to your Apple Health data to give more personalized health answers
OpenAI brings personalized health conversations to ChatGPT
Health in ChatGPT

OpenAI is expanding ChatGPT into a new category with the launch of Health in ChatGPT, a feature that allows users to securely connect health information from Apple Health and supported medical records. The feature is rolling out to users in the United States and is designed to help people ask health-related questions with more personalized context, instead of relying on isolated conversations.

According to OpenAI, more than 300 million people use ChatGPT every week for health-related queries, ranging from understanding lab reports to preparing for doctor appointments.

Read more
These are the mice I’d recommend for Back-to-school
The right mouse can outlast an entire degree. These are the ones worth picking up.
Satechi Slim EX Wireless Mouse These Are the Mice I'd Recommend for Back-to-School featured

A good mouse doesn't get nearly as much attention as a laptop, but it's one of those upgrades that quietly makes a difference every single day. Whether it's powering through assignments, editing photos, attending online classes, or squeezing in a few rounds of Valorant after lectures, the right mouse can make long hours at a desk far more comfortable. After looking through this year's options, these are the five mice I'd actually recommend for the Back-to-School season. They each serve a different purpose, which means there's something here whether gaming, productivity, or portability is the priority.

Satechi Slim EX Wireless Mouse

Read more