US says North Korean malware Volgmer and Fallchill lurking in computer networks; suspect hacker group Hidden Cobra

US claims that malware Volgmer and Fallchill developed in North Korea is still lurking in many computer networks, giving hackers backdoor access to government, financial, automotive and media organisations

AFP November 15, 2017 08:10:13 IST
US says North Korean malware Volgmer and Fallchill lurking in computer networks; suspect hacker group Hidden Cobra

Washington: US authorities said malware developed in North Korea is still lurking in many computer networks, giving hackers backdoor access to government, financial, automotive and media organisations.

An alert issued by the Department of Homeland Security warned of surreptitious activity by the so-called "Hidden Cobra" hacker group, also known by the name "Lazarus."

US says North Korean malware Volgmer and Fallchill lurking in computer networks suspect hacker group Hidden Cobra

Representational image. Reuters

US officials earlier this year blamed the group for a series of cyberattacks dating back to 2009, saying it was linked to the Pyongyang government.

In Tuesday's warning, the DHS Computer Emergency Response Team (CERT) said the hacker could still maintain a presence on victims' networks with the aim of "further network exploitation."

The report said some networks could be infected with the Volgmer "backdoor Trojan" or a remote administration tool known as Fallchill, which can give hackers complete control of a system.

It said FBI investigators suspect the Fallchill tool has been used since 2016 and Volgmer since 2013.

Private security analysts refer to Hidden Cobra as the "Lazarus" group of hackers linked to North Korea and likely behind a series of multimillion-dollar cyber thefts from banks around the world.

Some analysts say the Lazarus group may also have been behind the WannaCry ransomware outbreak earlier this year.

Hackers in the Hidden Cobra or Lazarus group have been active since 2009 and "have leveraged their capabilities to target and compromise a range of victims," according to a DHS report in June.

"Some intrusions have resulted in the exfiltration of data while others have been disruptive in nature."

DHS and FBI officials say the group "will continue to use cyber operations to advance their government's military and strategic objectives", according to the DHS report.

North Korea has denied orchestrating any cyber attacks, but the latest report comes amid rising tensions with the United States over the communist regime's nuclear testing programme.

Updated Date:

Subscribe to Moneycontrol Pro at ₹499 for the first year. Use code PRO499. Limited period offer. *T&C apply

also read

US govt reverses Trump-era policy to make asylum-seekers wait in Mexico
World

US govt reverses Trump-era policy to make asylum-seekers wait in Mexico

However, officials are warning people not to come to the border and to register on a website that the UN High Commissioner for Refugees is launching early next week

Donald Trump impeachment: Days after ex-US president's acquittal, Republicans ponder 'battle for soul of party'
World

Donald Trump impeachment: Days after ex-US president's acquittal, Republicans ponder 'battle for soul of party'

Republicans remain in a bind. Those who have openly opposed the ex-president have faced fierce blowback from the party's base. Many remain fearful of his tendency to exact payback

US coronavirus fatalities approach 500,000; Anthony Fauci terms it worst health crisis in past 102 years
World

US coronavirus fatalities approach 500,000; Anthony Fauci terms it worst health crisis in past 102 years

A year into the pandemic, fatalities have reached about 498,000 — roughly the population of Kansas City, Missouri, and just shy of the size of Atlanta