North Korean Hackers Tried to Steal Military Data

North Korean Hackers Tried to Steal Military Data

Diehl Defence anti-aircraft missiles are successfully intercepting Russian attacks on Kyiv, with a 100% hit rate. Germany also plans to install these systems on three new government aircraft for missile defense.

North Korean hacker group Kimsuky, working for military intelligence, used phishing to send fake job offers loaded with spyware to steal sensitive information.

Mandiant’s IT security experts detected Kimsuky targeting specific regions in Germany in early 2024, focusing on phone number registration processes.

In April, the hackers created a phishing site using a misspelled version of the defense company “Diehl Defence” to trick victims into clicking malicious links or downloading malware.

Hackers lured potential victims with fake job offers, offering attractive perks like high salaries and flexible working hours. Once victims clicked on the attached document, spyware was silently installed on their systems, giving the hackers unauthorized access to sensitive information.

According to ZDF, the hackers’ server, linked to Diehl Defence’s headquarters in Überlingen, hosted sophisticated spyware capable of capturing screenshots, accessing files, and downloading additional malicious programs. This allowed the hackers to maintain control over the infected systems without detection.

The “Kimsuky” hackers went a step further by creating a fake login portal on the “Überlingen” website, impersonating Deutsche Telekom. They tricked users into logging in with their Telekom credentials, stealing usernames and passwords in the process, which gave them further access to sensitive systems and data.

Diehl Defence declined to comment on a cyberattack on German entities, while the Federal Office for Information Security confirmed a hacker “Germany campaign” since May 2024.

North Korean hackers, likely from “Kimsuky,” are targeting nuclear researchers, security institutions, and arms companies, highlighting North Korea’s focus on acquiring sensitive technology and intelligence.

‍Follow Us on: Twitter, InstagramFacebook to get the latest security news!

By | 2024-10-09T23:03:38+05:30 September 30th, 2024|BOTNET, Compromised, Exploitation, malicious cyber actors, phishing, Security Advisory, Security Update|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!