Cyber warfare

US charges North Korea agent over Sony Pictures hack and WannaCry

The U.S. Department of Justice charged a North Korea agent over WannaCry and 2014 Sony Pictures Entertainment Hack.

The U.S. Department of Justice announces charges against a North Korean government spy that was involved in the massive WannaCry ransomware attack and the 2014 Sony Pictures Entertainment hack.

“the Justice Department charged on Thursday in a 174-page criminal complaint that detailed how hackers caused hundreds of millions of dollars’ worth of damage to the global economy.” states the NYT.

“Only one North Korean, Park Jin-hyokwas named — charged with computer fraud and wire fraud in the 2014 hack of Sony Pictures Entertainment.”

The individual charged by the US DoJ is Park Jin Hyok, an expert that works for North Korean military intelligence agency Reconnaissance General Bureau (RGB).

The man, also known as Pak Jin Hek, is also linked to the dreaded Lazarus APT Group.

The complaint against Mr. Park was filed under seal on June 8, just a few days before the summit meeting between Trump and Mr. Kim in Singapore.

The complaint also reports of a hacking unit working for North Korea’s intelligence agency, that operates out of China and other Asian nations

The 2014 Sony Pictures Entertainment hack was carried out by Pyongyang in retaliation for the production of the comedic film “The Interview” that mocks the North Korean leader Kim Jong Un.

At the time, the US law enforcement suspected the involvement of North Korea’s Unit 121, which is the group of hackers working under the direction of the General Bureau of Reconnaissance.

Hackers wiped many computers from the company and exfiltrated over 200GB of sensitive data, including upcoming movie scripts, celebrities phone numbers, employees data versions of then-unreleased films.

WannaCry infected 200,000 computers across 150 countries in a matter of hours after the beginning of the massive attack, it took advantage of a tool named “Eternal Blue”, originally created by the NSA, which exploited a vulnerability present inside the earlier versions of Microsoft Windows. This tool was soon stolen by a hacking group named “Shadow Brokers” which leaked it to the world in April 2017.

The ransomware infected systems in any industry and also targeted critical infrastructures such as hospitals and banks.

The US intelligence highlighted that North Korea hackers were free to operate from Chine. Chosun Expo Joint Venture helped fund North Korean hacking groups by covering their activities with legitimate programming work from an office in Dalian, China. According to the complaint, some customers were aware the employees “were North Korean computer programmers connected to the government.”

Mr. Park, who worked there from 2011 to 2013, and his colleagues were overseen by a company manager and North Korean political attaché́, the Justice Department said.

Hyok worked in China from at least 2011 to 2013 and returned to North Korea shortly before the attack against Sony Pictures in November 2014.

The investigation is still ongoing, this kind of investigations are very difficult and cannot leverage classified information from the intelligence agencies

“In order to get admissible evidence,” John Carlin, the former head of the Justice Department’s National Security Division, “prosecutors have to work through any issues the intelligence community might have.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs –  Sony Pictures, North Korea)

[adrotate banner=”5″]

[adrotate banner=”13″]

 

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

42 mins ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

7 hours ago

US offers a $10 million reward for information on four Iranian nationals

The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…

14 hours ago

The street lights in Leicester City cannot be turned off due to a cyber attack

A cyber attack on Leicester City Council resulted in certain street lights remaining illuminated all…

15 hours ago

North Korea-linked APT groups target South Korean defense contractors

The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…

1 day ago

U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity

The U.S. Department of State imposed visa restrictions on 13 individuals allegedly linked to the…

2 days ago

This website uses cookies.