Microsoft takes down 50 North Korean hacking sites

Microsoft takes down 50 North Korean hacking sites
(Image credit: TheDigitalArtist / Pixabay)

Microsoft has successfully launched a court action to take control of fifty domains used for spear phishing attacks.

These attacks apparently came from a hacking group affiliated with North Korea, and collected user account details in order to both steal data as well as upload malware in an attempt to infect IT systems.

Spear phishing

The phishing emails were targeted at employees of governments, international agencies, as well as university staff, mostly based in the US, Japan, and North Korea. The spoof emails claimed that the user’s account was compromised, advising them to login to change their account details.

Of course, the links went to domain names that attempted to look official in order to record the user account details. Once inputted, hackers could use this login information to access the user’s official account. From there, they would not just access and copy user information, but also install malware in an attempt to infiltrate any IT systems the user had access to.

Additionally, the hackers were able to set up a command to copy any new emails to the user without the user realizing, even when the account password had been changed.

According to Microsoft, the court action allowed Microsoft to take control of the fifty domain names used in the attack.

While presented as a victory against cyberattacks, domain names are cheap and it would be easy for the hacking group to simply copy their phishing attacks onto a new set of domains.

Additionally, users are reminded that in the event of ever receiving an email claiming your account details have been compromise, DON’T click on the links in the email, but instead visit the main website directly in order to avoid what is one of the most common yet easiest to avoid web attacks.

Via ZDnet.

Brian Turner

Brian has over 30 years publishing experience as a writer and editor across a range of computing, technology, and marketing titles. He has been interviewed multiple times for the BBC and been a speaker at international conferences. His specialty on techradar is Software as a Service (SaaS) applications, covering everything from office suites to IT service tools. He is also a science fiction and fantasy author, published as Brian G Turner.

Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why