Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Denver news in your inbox

Catch up on the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Des Moines news in your inbox

Catch up on the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Minneapolis-St. Paul news in your inbox

Catch up on the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tampa Bay news in your inbox

Catch up on the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Charlotte news in your inbox

Catch up on the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Photo: Pyeongyang Press Corps/Pool/Getty Images

For several years, North Korea has been conducting a spree of bank robberies online. A new report from FireEye makes clear that a recent attempt to "name and shame" a North Korean government-affiliated hacker did nothing to curtail the digital heists, and sanctions have only made Pyongyang more eager to steal money. But experts think the U.S. still has other levers it can pull.

Why it matters: While the Trump administration is trying to play nice with Kim Jong-un ("We fell in love," said Trump at a rally Saturday night), the continuing heist campaign has attempted to steal more than $1 billion total.

Background: After years of crippling sanctions, the Kim regime began using part of its cyber program to generate the cash North Korea needed to run. According to FireEye, North Korea began robbing banks in 2014, shortly after being sanctioned for its third nuclear test.

  • Since then, the pile of international sanctions has only grown, including some for cyberattacks. Those sanctions appear to have encouraged more North Korean thefts.

The FireEye report, released Wednesday, is an argument that North Korea's bank hackers are separate and distinct from the country's other hacking ventures.

  • The bank robbers, which FireEye calls "APT38," operate by hacking a victim and requesting large transfers over the SWIFT interbank messaging system. "The attack ends in destructive, disk-whipping malware. They want to destroy systems not only to delete evidence, but to give them time to launder funds," said Nalani Fraser, threat intelligence manager at FireEye.
  • APT38 is one of a number of financial crime operations in North Korea. Other hackers, for example, rob cryptocurrency exchanges.

Name and shame: In September, the Trump administration publicly named, sanctioned and announced plans to charge North Korean Park Jin Hyok for, among other things, helping develop the WannaCry malware.

  • The tactic, often called "naming and shaming," did not decrease APT38 attacks.

The diplomatic play: Trump could make financial attacks a deal breaker in nuclear negotiations with North Korea, suggested Andrew Grotto, former senior director for cybersecurity policy to Presidents Obama and Trump and a current fellow at Stanford's Center for International Security and Cooperation.

  • "The Trump administration pulled out of the Iran deal in part because it didn’t address other issues, like hacking," he said. "If they’re consistent, they would try to address bank robbery."

The legal moves: Grotto notes financial crimes require an external, international network of collaborators — from money launderers to people who identify soft targets to attack. If we can't arrest hackers in North Korea, we could arrest confederates elsewhere.

  • Since North Korea lacks the internet infrastructure needed to launch cyberattacks, many of its attacks are launched from other countries. Michael Daniel, former White House cybersecurity coordinator and the current president and CEO of the Cyber Threat Alliance, believes the U.S. could press countries to cough up North Koreans.

Returning fire: And, said Daniel, the United States could use cyber means to disrupt the networks.

Or all of the above: "It would likely be a complex mix of tactics," said Daniel.

Go deeper

55 mins ago - Politics & Policy

Stalemate over filibuster freezes Congress

Illustration: Sarah Grillo/Axios

Senate Majority Leader Chuck Schumer and Mitch McConnell's inability to quickly strike a deal on a power-sharing agreement in the new 50-50 Congress is slowing down everything from the confirmation of President Biden's nominees to Donald Trump's impeachment trial.

Why it matters: Whatever final stance Schumer takes on the stalemate, which largely comes down to Democrats wanting to use the legislative filibuster as leverage over Republicans, will be a signal of the level of hardball we should expect Democrats to play with Republicans in the new Senate.

Dave Lawler, author of World
1 hour ago - World

Biden opts for five-year extension of New START nuclear treaty with Russia

Putin at a military parade. Photo: Valya Egorshin/NurPhoto via Getty

President Biden will seek a five-year extension of the New START nuclear arms control pact with Russia before it expires on Feb. 5, senior officials told the Washington Post.

Why it matters: The 2010 treaty is the last remaining constraint on the arsenals of the world's two nuclear superpowers, limiting the number of deployed nuclear warheads and the bombers, missiles and submarines which can deliver them.

Updated 2 hours ago - Technology

Facebook refers Trump ban to independent Oversight Board for review

Photo: Alex Edelman/AFP via Getty Images

Facebook's independent Oversight Board has accepted a referral from the platform to review its decision to indefinitely suspend former President Trump.

Why it matters: While Trump critics largely praised the company's decision to remove the then-president's account for potential incitement of violence, many world leaders and free speech advocates pushed back on the decision, arguing it sets a dangerous precedent for free speech moving forward.