Site navigation

State-backed Hackers Pose as Journalists to Breach Networks

Michael Edgar

,

North Korea Iran
State-backed hackers have been found to exploit journalist’s identities to spread malware.

Recent findings from have shed light on the clandestine operations of state-backed hacker groups from both Iran and North Korea, who are employing tactics to infiltrate networks and spread malware under the guise of legitimate journalists.

APT42, a threat actor associated with Iran’s Islamic Revolutionary Guard Corps Intelligence Organisation (IRGC-IO), was identified as carrying out social engineering attacks, including posing as journalists, to breach corporate networks and cloud environments of targets primarily in Western and Middle Eastern regions. This group, documented by Mandiant since 2022, has conducted over 30 operations across 14 countries, targeting a diverse array of entities such as media outlets, educational institutions, NGOs, and legal services.

Utilising online personas, APT42 operatives initiate email exchanges with potential victims, using domains that closely resemble those of reputable organisations. These emails contain links to seemingly innocent documents related to conferences or news articles, designed to establish trust and lure unsuspecting targets into clicking. 

Once clicked, victims are redirected to fake login pages mimicking well-known services like Google or Microsoft, enabling the hackers to harvest sensitive credentials and multi-factor authentication tokens for unauthorised access to corporate networks and cloud environments.

Meanwhile, the North Korean threat actor known as Kimsuky has also been implicated in espionage campaigns targeting policy experts and analysts. 

Exploiting weak email security measures and poorly configured DMARC (Domain-based Message Authentication, reporting, and conformance protocols, Kimsuky actors pose as legitimate journalists or academics, particularly in the realm of East Asian affairs. 


Recommended reading


By impersonating trusted individuals and organisations, they aim to gain access to private documents, research materials, and communications pertaining to geopolitical events and foreign policy strategies.

According to a joint advisory on the matter, the Kimsuky campaigns are highly targeted with extensive research and preparation behind each attack. 

The tactics employed by both APT42 and Kimsuky underscore the evolving nature of state-sponsored cyber threats and the need for robust cybersecurity measures to mitigate risks. 

Organisations are urged to enhance their email security protocols, educate employees about the dangers of social engineering attacks, and remain vigilant against suspicious communications. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data