21.5 C
Munich
Monday, June 5, 2023

A hacker attack on the Polish military industry. They are seduced by fake job offers

Must read

Foreign hackers tried to obtain classified information about the Polish defense industry. Employees were supposed to receive infected emails disguised as great job offers at a well-known American company. However, there was a hitch.

Cybersecurity experts from ESET have published a report summarizing the latest activities of international cybercriminals. The focus was on APT hacker groups (from Advanced Persistent Threat), i.e. those that use best practices and constantly harass organizations around the world. The target of one of the attacks was supposed to be employees of a Polish defense industry company.

Hackers from Lazarus Group attacked the Polish defense industry

The Lazar group was responsible for organizing the action against the Poles. This is one of the most notorious cybercriminal groups working on behalf of North Korea. Their specialty is international espionage.

The attack, dated Q1 2023, used job offers. The Koreans began to communicate with employees of one of the companies providing services in the defense industry. The criminals had to quite cleverly pretend to be employees of the American Boeing aircraft concern.

The hacker sent the victim a message with an attachment, purporting to be a job offer in the form of a PDF file. However, the file contained an infected version of a file reader based on SumatraPDF. There was also the ScoringMathTea malware. At the same time, the ImprudentCook file downloader was running in the background.

According to ESET, the recent attack on a Polish company fits into Lazarus’ broader strategy. Back in 2020, the Koreans tried their luck with Operation In(ter)ception, a rather similar promotion with job offers aimed at employees of European companies from the aviation and defense industries.

Hackers from Russia and China are still active

Experts also warn of an ever-growing threat from APT groups acting on behalf of hostile regimes. The Russians should be especially active, attacking targets in Europe again and again, especially in Ukraine.

Pro-Kremlin groups include: Sandworm, Gamaredon, Sednit or Duke. Recently, they have persistently attacked Ukrainian government institutions and repeatedly tried to deceive high-ranking officials in many EU countries.

In Asia, groups associated with China have left their mark. The Ke3chang and Mustang Panda groups developed and used new proprietary Trojans. The MirrorFace team attacked targets in Japan, while the ChattyGoblin team worked with companies in the Philippines.

Designed by: Krzysztof Sobepan
Source: Press materials // ESET

Source: Wprost

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article