- Sputnik International
Asia
Find top stories and features from Asia and the Pacific region. Keep updated on major political stories and analyses from Asia and the Pacific. All you want to know about China, Japan, North and South Korea, India and Pakistan, Southeast Asia and Oceania.

North Korean Hackers Make Millions Stealing from Banks - Report

© Photo : PixabayHacker
Hacker - Sputnik International
Subscribe
A new report from a for-profit US security firm claims North Korean hackers have robbed banks around the world of a fortune – and such operations remain an “active and serious threat.” Reports indicate hundreds of millions of dollars have been stolen by the hackers.

Northern Virginia-based FireEye said in a Wednesday blog post that a group dubbed APT38 "is responsible for conducting financial crime on behalf of the North Korean regime, stealing millions of dollars from banks worldwide."

Cyber space - Sputnik International
Justice Department Charges Alleged North Korean Hacker for WannaCry, Sony Hacks

Over the past four years, the group has conducted operations against targets in 11 countries and 16 organizations and "has attempted to steal over $1.1 billion from financial institutions," the report says. The group moves very slowly and can be inside of a target network for extended periods before being noticed, according to FireEye, which said APT38 has remained, on average, "within a victim network for approximately 155 days."

"This is a very insidious group… it will destroy networks and steal millions and millions of dollars," a senior executive at the company said Wednesday, Politico reports.

The group is financially motivated, according to FireEye, though it also engages in cyber information gathering and reconnaissance missions. Notably, FireEye accused APT38 of penetrating SWIFT servers as part of a sophisticated money laundering scheme.

FireEye claimed in August that hundreds of Facebook and Twitter accounts "originated" in Iran, and those accounts were then banned by the platforms. Weeks later, the US State Department cited the banned accounts in a statement on "Iran's Threat to Cybersecurity."

​Web developer Chris Garaffa told Sputnik News via email that one should be cautious before classifying the hacking claims as consensus facts. "Unlike most US and western media outlets that will immediately publish the conclusions of the report without much further analysis, it will take security researchers some time to review the FireEye document against other known information and make a conclusion," the technologist said.

"While FireEye is a knowledgeable and successful organization, they are still a private company based in the US that serves primarily US-based government agencies and companies, and their leadership has ties to the Pentagon and defense industries," according to Garaffa.

"They are not necessarily an impartial actor, and this needs to be taken into consideration."

People are silhouetted as they pose with laptops in front of a screen projected with a Google logo, in this picture illustration taken in Zenica October 29, 2014. - Sputnik International
Google Cites CIA-Backed Firm in Ban of Allegedly Iran-Backed Accounts

"Just where do spies go to get their toys? Well, James Bond had ‘Q,' and the CIA has In-Q-Tel," according to a D&B Hoovers description of In-Q-Tel, a not-for-profit venture capital firm headquartered in Virginia. In-Q-Tel and FireEye signed a "strategic investment and technology development agreement" in 2009, though FireEye "clarified" in 2014 that it "was never a CIA company."

Garaffa also says there is an element of "Western hypocrisy" in play, since "the US government and its allies regularly launch cyber attacks on other countries… when the US has declared a cyber war against the rest of the world, it would absolutely make sense for its targets to both defend themselves and retaliate."

Newsfeed
0
To participate in the discussion
log in or register
loader
Chats
Заголовок открываемого материала