|
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray and Amberleigh Jack. This week's edition is sponsored by Permiso Security. You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.
Listen here Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less FunNorth Korea will have to rein in its pet hackers after seemingly losing control over them. Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit. Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme". Punishment for those involved will reportedly be extreme, with one official saying "It will be hard for the entire family line to survive". Grim. The outlet also says officials in North Korea's Reconnaissance General Bureau, the organisation responsible for cyber espionage, are worried that the scandal could even roll uphill and claim their scalps. We expect, therefore, that this incident will result in some substantial tightening of operational controls. North Korea's state-sanctioned cyber crime operations can be lumped into three buckets: high-value targeted cryptocurrency hacks, broad-based fraudulent worker scheme, and ransomware extortion operations. There is some evidence that in addition to former operatives stealing from North Korean banks, the government there is also losing control over its ransomware operators. North Korea first dipped its toe into ransomware by developing its own strains. In 2021 and 2022 one of its hacker groups, Andariel, created two different ransomware strains that it used on organisations in the US, South Korea and Japan, including against the American health sector. After dabbling in roll-your-own ransomware, in recent years North Korean hackers began collaborating with the ransomware-as-a-service (RaaS) ecosystem. Threat intelligence reports say that Andariel used Play ransomware in 2024 and Medusa ransomware in 2025. Last week, South Korean security firm AnhLab reported that a state-controlled North Korean hacker group is also collaborating with Gunra ransomware. It's unclear whether this collaboration is state sanctioned or not. North Korean cyber units are supposed to funnel stolen funds into the state's coffers. By design, however, RaaS offerings help skilled individuals profit from their hacks. Given the recent hack of the country’s banks, and this news of DPRK operators getting cozy with criminal outfits, we suspect that RGB officials might start to look at RaaS operations a bit differently. If you're personally on the hook for extreme punishments if your underlings go rogue, why put them in a position where they're tempted to put their hands in the cookie jar? So what's next for North Korean state-sponsored hacks? Scaling back its ransomware operations is one possibility, but it is not the only option. We suspect a strong tightening of controls on its hacking teams in general is more likely. There is good evidence that North Korea uses very tight internal controls on its scam IT workers already. North Korean defectors have described constant surveillance and screen monitoring, isolation, movement restrictions and strict work quotas. It doesn't appear that the same level of control is currently applied to the country's hackers. A 2014 report says they were viewed as the elite of the military. Rather than being intensively surveilled, they had privilege and more freedom. That's almost certainly a thing of the past. Being a state-backed DPRK hacker is about to be a lot less fun. Cyber War Is Here, and America Is Politically UnpreparedMultiple cyber provocations targeting America's water sector have revealed how unprepared the US is to deal with the political fallout of cyber attacks against critical infrastructure. The Washington Post reported US intelligence agencies have determined that Iran is behind the attacks on water facilities in Minnesota that we covered last week. Now, at least a dozen states have experienced similar disruptions. Per Risky Bulletin: Some of the new public incidents have been reported in Clayton County, Georgia and the city of Duchesne, Utah. Customers were left low pressure or no water in Clayton County in the middle of the night last week. In Utah, the cyberattack made pumps run dry while their control panels said they were pumping water. The incident impacted an oilfield wastewater disposal site but did not cause any environmental damage.
A CISA advisory about the escalating activity says that it has "resulted in boil water notices" and led to "sustained manual operations". This campaign is historically significant. As far as we know, it is the first time a country has responded to kinetic attacks in the cyber domain by targeting an aggressor's critical infrastructure. The direct impact of the hacks on water supply have been manageable so far, which is consistent with what we've seen in other conflicts over the last several years. The effects of wartime cyber attacks are relatively short-lived and they have been most useful when combined with tightly orchestrated conventional operations, such as America's 2025 strikes against Iranian nuclear facilities or its capture of Venezuelan President Nicolas Maduro. Without complementary conventional action, Iran's attacks on America's water systems don't amount to much. Having said that, the strategic goal of the campaign is to erode political support for the war. In our view, widespread publicity without accompanying devastation is the perfect way to achieve that goal. This campaign was entirely predictable. As we've written before, if you bomb Iran, you should expect cyber operations against critical infrastructure in return. Even as far back as 2013 Iranian hackers compromised control systems at a New York state dam and tried to affect its operation. We're only surprised that this current campaign took so long to spin up. The US government's response has so far been fairly muted. CISA has advised organisations to remove targeted devices from the internet and to connect to them using VPNs or gateway devices, to enable passwords and use strong ones, and allowlist IP addresses for remote access. Since it was pretty clear that Iran would respond to missiles with cyber, we think running a campaign to fix these vulnerabilities before military action against Iran would have left the US government in a much better place to deal with this campaign. It's true that a preparatory cyber security drive like this wouldn't have made America's water infrastructure perfectly secure. It's too big, too decentralised and too resource constrained. It could, however, have made a political difference. "We understand the problem, we've been putting mitigations in place, some systems remain vulnerable but we can assure everyone the impacts will be limited". In other words: We've got this under control. As it stands, despite the campaign's predictability, the Trump administration is on the back foot. President Donald Trump even blamed Minnesota and its officials for the attacks. That's some pretty bonkers politics, and exactly the sort of sound byte Iran will chalk up in the "win" column. Watch James Wilson and Tom Uren discuss this edition of the newsletter: Three Reasons to Be Cheerful This Week:- Chrome in the AI era: Google's Chrome team has described how they are using AI to make the browser safer by improving vulnerability discovery and patching. The team uses AI agents coupled with harnesses to carry out find and fix vulnerabilities as well as to triage external bug reports. Google says that over the previous two stable releases it fixed 1072 security bugs.
- OpenAI disrupts Cambodian scammers: OpenAI announced last week that it had disrupted a Cambodia-based scam operation that was using ChatGPT to support "investment, romance, gambling and impersonation schemes". The good news here is that a tip from WhatsApp led OpenAI to what it found to be a coordinated network of accounts. We are all in favour of more coordination to counter scam compounds.
- Romance scammer gets seven years: The US Department of Justice announced last week that Derrick Van Yeboah was sentenced to 85 months in prison for his role in romance and business email compromise scams. The Ghanaian was involved in a criminal organisation that stole and laundered more than USD$100 million from dozens of victims. The DoJ says Van Yeboah "personally perpetrated many of the romance scams by impersonating fake romantic partners" with victims. His victims transferred millions of dollars to the gang.
In this Risky Business sponsor interview, James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.
|