Israel Says It Beat Attack by North Korean Cyber Group Under U.S. Sanctions
Israel said Wednesday that it thwarted a North Korean cyber group’s attempt to steal sensitive information from leading defense companies in the country.
Israel’s Defense Ministry identified the group as Lazarus and said it is backed by a foreign country, though it didn’t name North Korea.
Lazarus was sanctioned by the U.S. last year. The U.S. said the state-sponsored North Korean group has a history of high-profile global hacking attempts aimed at foreign businesses, government agencies, financial-services infrastructure, private corporations and the defense industry.
Israel’s Defense Ministry said members of Lazarus built fake profiles on LinkedIn to contact employees of Israel’s leading defense companies and offer them jobs. In the process of sending job offers, members of the group tried to compromise computers of employees, access their corporate networks and obtain sensitive security information.
The North Korean hackers also tried to hack companies’ official websites, the ministry said.
It didn’t identify which Israeli defense companies were targeted but said their networks weren’t harmed or disrupted. It said it has launched an investigation into the attempted hack but didn’t say when it occurred.
North Korea has denied involvement in hacking attacks.
South Korean officials have sorted North Korea’s cyber-attacking operation into three teams: The A team—often called Lazarus by foreign research firms—attacks foreign banks and companies; the B team focuses on South Korea; and the C team blasts out emails and collects information, they say.
Researchers say North Korea has expanded its efforts to target global institutions.
The U.S. said Lazarus was behind the 2014 hack of Sony Pictures Entertainment Inc. and the 2017 WannaCry ransomware attacks, which scrambled computer systems in more than 100 countries, including that of the U.K.’s National Health Service.
Earlier this year, Israel said it thwarted an Iranian attempt to disrupt its water supply with a cyberattack. It later targeted the command-and-control system at an Iranian port in Bandar Abbas, according to a foreign security official with knowledge of the Israeli operation. That resulted in dozens of cargo ships congesting the harbor.
Photo: Israeli soldiers during an exercise last week in the Israel-occupied Golan Heights, near the disputed border between Syria and Israel. - PHOTO: AYAL MARGOLIN/JINI/XINHUA/ZUMA PRESS