Bureau 325: North Korea and its state hacking

B2B Cyber ​​Security ShortNews

Share post

State-led hacker attacks are usually assigned to one of the "Big Four": Russia, China, Iran or North Korea. North Korea's early attacks were primarily directed at South Korea, but in recent years Western countries have also become targets of their financially motivated and espionage-related operations.

Based on current research, Mandiant has compiled an overview of North Korean hacking groups and provides information about their connection to the North Korean government. Historically, most North Korean cyberattacks have been attributed to the notorious Lazarus group. New research suggests that North Korea's government has various cyber entities that are distinct and have recently been actively regrouped.

Bureau 325 as a multi-assault force

Among other things, the recently founded hacker group "Bureau 325" is examined in more detail, the importance of which has increased rapidly. It is referred to as North Korea's "Swiss Army Knife". A comment from Michael Barnhart, Principal Analyst at Mandiant, on Bureau 325:

“The activities of the Bureau 325 group have developed significantly in a short period of time. They now range from trying to get information about the COVID-19 vaccine to crypto heists to stealing nuclear trade secrets. This suggests that "Bureau 325" is North Korea's new "all-star squad." We assume that there are several sub-units within the group, each with their own areas of specialization.

Lazarus only part of the attack force

The restructuring shows that North Korea wants to become as good as China when it comes to cyber threats. Their cyber units are extremely mobile now that they have consolidated. This is a dangerous group and security teams need to learn how to protect their organizations from it. Because we expect to see more from this hacker group.”

More at Mandiant.com

 


About Mandiant

Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response. With decades of experience on the cyber frontline, Mandiant helps organizations confidently and proactively defend against cyber threats and respond to attacks. Mandiant is now part of Google Cloud.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more