Lessons from a US Hacker Who Fought Back against North Korea

Published in Sankei Shimbun
(Japan) on 25 February 2022
by Mihoko Matsubara (link to originallink to original)
Translated from by T Kagata. Edited by Laurence Bouvard.
Cyberattack That Hit North Korea

On Jan. 26, a cyberattack struck North Korea, paralyzing the internet for about six hours. It appears to have been a Distributed Denial of Service attack that sent more data than the target's servers and websites could handle, which caused them to go down.

Problems connecting to the websites of the Ministry of Foreign Affairs of North Korea, Koryo Airlines, the official newspaper of the Workers' Party of Korea, the Korean Central News Agency and other websites, as well as the official government website Naenara, continued until the next morning.

The attack took place at a time when tensions were running high after North Korea had launched its fifth missile this year. Therefore, some thought that foreign governments may have tried to convey a message to North Korea through a cyberattack to stop the country's threat by force.

In reality, however, it was not the government, but an American hacker who carried out this attack. According to a Feb. 2 interview by Wired, a U.S. technology information site, this person, who calls himself "P4x," was retaliating against a cyberattack by a group of North Korean hackers.

In 2020 and 2021, a group of North Korean hackers targeted Western countries' cybersecurity experts who were investigating vulnerabilities in their systems. It is believed that they were trying to steal the tools that the researchers were using and the vulnerabilities they were investigating.

Why Did You Fight Back Alone?

This group of North Korean hackers created fake accounts on social media sites such as Twitter and LinkedIn and approached their target researchers posing as cybersecurity bloggers. They offered to collaborate on vulnerabilities and sent them messages with computer viruses when they were on board.

P4x was one of the victims of this attack, but fortunately the damage was prevented.

He was aware his actions were illegal, but the reason he dared to fight back was not only because he was angry at North Korea for attacking him, but also because he was angry at the U.S. government for neglecting the researchers who had suffered from the damage for a year. He thought that if he didn't fight back then, they were going to keep attacking the researchers, and he decided to take action.

However, P4x does not believe that he was able to strike a blow against North Korea, which is less dependent on the internet.

P4x told Wired that North Korea had left many vulnerabilities in its IT systems. North Korea will thoroughly review and strengthen its security in order to prevent future cyberattacks. If this happens, the U.S. government and its allies will be forced to drastically revise their future cyber operations against North Korea, and in the mid- to long-term, the damage to the U.S. government and others may be greater than the damage suffered by North Korea.

Protect Individuals from Cyberattacks

The motive behind this incident highlights the sophisticated cyberattacks carried out by highly skilled foreign government-affiliated hackers targeting individuals on social media and the inadequate victim support. Moreover, the number of cyberattacks on personal social media accounts is expected to increase this year, and urgent countermeasures are needed.

Cyberattackers target the weakest point in the defense and try to break in. The social media accounts, private emails and private devices of individuals such as government officials, executives and researchers of the latest technology are more vulnerable to intrusion than the systems protected by corporations and governments with high security systems.

Foreign government-affiliated hacker groups use human network information and hijacked accounts as footholds to create even more sophisticated spoofed emails to launch cyberattacks against governments and corporations and steal intellectual property-related information, such as security and the latest technologies. Not only the U.S., but also Japan has become a target of such attacks.

Even cybersecurity experts struggle with the attacks by North Korean government-affiliated hackers, so it would be more so if you are not an expert.

However, as P4x points out, the U.S. government has so far not focused much on warning and educating individuals in advance and counseling and helping victims.

Japan should also learn a lesson from this incident and reaffirm that cyberattacks targeting individuals are the first step of cyberespionage that can damage security and economic security.

Furthermore, it is necessary to thoroughly inform the public about the reasons why individuals are targeted by cyberattacks, the latest methods of attacks and countermeasures to prevent damage. In order to do this, it is essential that the government agencies and companies where the people work also cooperate to raise awareness and publicize their activities. There is also a need for consultation services for victims.

The National Police Agency, the Metropolitan Police Department and the Osaka Prefectural Police Department have recently begun actively holding briefing sessions for companies, universities and research institutes, as well as offering individual consultations. If such awareness-raising and support activities are expanded throughout the country, it will serve as a deterrent against cyber espionage by foreign governments. There is no time to waste for public and private sectors to work together to strengthen cybersecurity.


北に反撃した米国ハッカーの教訓 
NTTサイバー専門家・松原実穂子
2022/2/25 08:00


|北朝鮮を襲ったサイバー攻撃

1月26日、北朝鮮をサイバー攻撃が襲い、インターネットが約6時間麻痺(まひ)に陥った。標的のサーバーやウェブサイトの処理能力を超える大量のデータを送りつけ、ダウンさせる分散型サービス拒否(DDoS)攻撃だったようだ。

北朝鮮外務省、高麗航空、朝鮮労働党機関紙「労働新聞」や朝鮮中央通信などのウェブサイトや政府の公式サイト「ネナラ」への接続障害は翌朝まで続いたという。

この攻撃が起きたのは、北朝鮮が今年5回目のミサイル発射を実施、緊張が高まっていた時期である。そのため、武力による威嚇をやめるよう、外国政府が北朝鮮にサイバー攻撃を通じてメッセージを伝えようとしたのではないかとの見方もあった。

ところが実際には、この攻撃を実行したのは政府ではなく、なんと一人の米国人ハッカーだった。米テクノロジー情報サイト「ワイアード」の2月2日付インタビュー記事によると、「P4x」を名乗るこの人物は、北朝鮮のハッカー集団から受けたサイバー攻撃に報復するため、反撃したのだという。

2020、21年、北朝鮮のハッカー集団が、システムの脆弱(ぜいじゃく)性について調べている西側諸国のサイバーセキュリティの専門家たちを狙った。研究者たちの使っているツールや調査中の脆弱性情報を盗むためだったと考えられる。


|単独で反撃に出た理由

この北朝鮮ハッカー集団は、ツイッターやリンクトインなどのソーシャルメディア上で偽アカウントを作り、サイバーセキュリティのブロガーを装って標的の研究者に近づいた。脆弱性の共同研究を持ちかけ、相手が乗ってくると、コンピュータウイルス付きのメッセージを送り付けたのである。

「P4x」もこの攻撃を受けた一人だったが幸い被害は防げた。

自分の行為の違法性を自覚した上であえて反撃したのは、攻撃してきた北朝鮮への怒りもさることながら、被害を受けた研究者たちを助けようとせず、1年間放置した米国政府への憤りが募ったからだ。「ここで反撃しなければ、やられっぱなしになる」と考え、一矢報いる決意をしたのだという。

ただし、インターネットへの依存度の低い北朝鮮に打撃を与えられたとは、「P4x」自身考えていない。

「P4x」は、北朝鮮がITシステムの脆弱性を数多く放置していたと「ワイアード」に語っている。北朝鮮は、今後のサイバー攻撃被害を防ぐため、徹底的にセキュリティを見直し、強化するだろう。そうなれば米国政府や同盟諸国は将来の北朝鮮へのサイバー作戦の大幅修正を余儀なくされ、中長期的には、北朝鮮の受けた打撃より、米国政府などへの打撃の方が大きいのではないか。


|個人をサイバー攻撃から守れ

今回の事件の動機から浮き彫りになったのは、高度なスキルを持つ外国の政府系ハッカー集団が個人を狙ってソーシャルメディア上で繰り広げる巧妙なサイバー攻撃と、不十分な被害者支援だ。しかも、個人のソーシャルメディア・アカウントを狙ったサイバー攻撃は今年一層増えると予想され、早急な対策が必要である。

サイバー攻撃者は最も守りの弱い箇所を狙い、侵入を試みる。企業や政府が高いセキュリティ体制で守っているシステムより、政府高官や経営層、最新技術の研究開発者などの個人のソーシャルメディアのアカウントや私用メール、私用端末の方が侵入しやすい。

外国の政府系ハッカー集団は、そこから集めた人脈情報や乗っ取ったアカウントを足がかりに、さらに巧妙ななりすましメールを作り、政府や企業にサイバー攻撃を仕掛け、安全保障や最新技術などの知的財産関連情報を盗もうとする。米国だけでなく、日本もこうした攻撃の標的となっている。

サイバーセキュリティの専門家でさえ北朝鮮の政府系ハッカー集団の攻撃に苦戦するのだから、専門家でなければ尚更(なおさら)だ。

しかし、「P4x」が指摘するように、今まで米国政府は、個人への事前の警告や啓発、被害者への相談・救済にそれほど注力してこなかった。

日本も、本事件から教訓を学び、個人を狙ったサイバー攻撃が安全保障や経済安全保障に打撃を与えるサイバースパイの第一歩であると再認識すべきであろう。

さらに、個人が何故サイバー攻撃で狙われているのかという理由と最新の攻撃の手口、その対策の周知を徹底し、被害を防止していく必要がある。それには、その人々が働いている政府機関や企業も協力しての啓発・広報活動が不可欠だ。被害に遭った際の相談窓口も求められる。

警察庁や警視庁、大阪府警は、最近、企業や大学、研究機関向けに積極的に説明会を開催し、個別相談も始めた。こうした周知・支援活動を全国に拡大していけば、外国政府によるサイバースパイ活動への抑止力にもなろう。官民一丸となってのサイバーセキュリティ強化が待ったなしである。(まつばら みほこ)
This post appeared on the front page as a direct link to the original article with the above link .

Hot this week

Austria: Maybe Trump’s Tariff Bludgeon Was Good for Something after All

Germany: Trump’s Offer and Trump’s Sword

Spain: Spain’s Defense against Trump’s Tariffs

Germany: Trump’s Selfishness

Australia: Trump Often Snaps at Journalists. But His Latest Meltdown Was Different

Topics

Germany: Trump’s Selfishness

Austria: Trump Ignores Israel’s Interests during Gulf Visit

Germany: Trump’s Offer and Trump’s Sword

Canada: A Guide To Surviving the Trump Era

Canada: Trump Prioritizes Commerce Over Shared Values in Foreign Policy Gamble

Australia: Another White House Ambush Sends a Message to World Leaders Entering Donald Trump’s Den

Australia: Trump Often Snaps at Journalists. But His Latest Meltdown Was Different

Germany: Trump’s Momentary Corrective Shift

Related Articles

Japan: Trump’s 100 Days: A Future with No Visible Change So Far

Japan: US Administration Losing Credibility 3 Months into Policy of Threats

Japan: US-Japan Defense Minister Summit: US-Japan Defense Chief Talks Strengthen Concerns about Single-Minded Focus on Strength

Japan: Trump’s Tariffs Threaten To Repeat Historical Mistakes

Hong Kong: China, Japan, South Korea Pave Way for Summit Talks; Liu Teng-Chung: Responding to Trump