Seized Server Confirms North Korean Link to Global Cyberespionage Campaign

Government officials provide security researchers with a seized server that confirms North Korea's Lazarus Group is behind the Operation Sharpshooter malware campaign.

Government officials hand security researchers a seized server that North Korean hackers use to launch Operation Sharpshooter, a targeted malware campaign against governments, telecoms, and defense contractors. McAfee confirms that the Lazarus Group operates this server, giving researchers unprecedented visibility into the adversary's command-and-control infrastructure. The hackers send malicious Word documents that run macro-code to download a second-stage implant known as Rising Sun, which steals valuable user data.

The examination of the server code reveals that Operation Sharpshooter is active far longer than initially believed, with operations dating back to September 2017. The campaign targets a much broader range of industries and countries than previously known, including financial services and critical infrastructure in Europe, the U.K., and the U.S. This discovery adds to the growing list of attributed attacks from the nation state, which includes the 2016 Sony hack and the 2017 WannaCry ransomware outbreak.

The server operates using standard PHP and ASP web languages, making the infrastructure easily deployed and highly scalable. It contains several specialized components that work together, including an implant downloader and a command interpreter that operates the Rising Sun implant through intermediate hacked servers to hide the broader command structure. Researchers note that the hackers utilize a factory-style approach to build this modular malware.

Read More at the original source →