Oct 24, 2019

Sophisticated hackers target UN and NGO North Korea-watchers

Hackers targeting nongovernmental humanitarian groups, including UN groups like UNICEF, sought to steal login credentials using sophisticated phishing sites, according to a new report by mobile security firm Lookout.

Why it matters: Lookout doesn't attribute attacks to specific actors, but the lures used to draw targets to the phishing sites were links only of interest to workers following North Korea issues. That suggests North Korea is a likely suspect here.

What they found: The phishing sites used a number of clever tricks.

  • For one, if users reached the phishing sites through any path other than the phishing URL, it forwarded the user to a legitimate site. That limits the hackers' exposure.
  • While most people believe a site won't see the login data they type into a website unless they hit submit, the sites used key loggers to steal login data even if they didn't.
  • Like many modern phishing campaigns, the site used SSL certificates — the encryption measures that produce the lock icon in the URL bar, which less sophisticated users are sometimes told to look for to thwart phishing. Also, the sites used long URL names, making it harder for people on mobile phones to notice inconsistencies there.

The sites were hosted by the Malaysian firm Shinjiru, Lookout's Jeremy Richards told Axios.

  • Shinjiru is a so-called bulletproof hosting service offering technical and legal protections for hackers. Using providers like Shinjiru raises an automatic red flag in Lookout's machine learning system.

Go deeper

Updates: George Floyd protests continue past curfews

Protesters on Tuesday evening by the metal fence recently erected outside the White House. Photo: Olivier Douliery/AFP via Getty Images

Protests over the death of George Floyd and other police-related killings of black people continued Tuesday night across the U.S. for the eighth consecutive day — prompting a federal response from the National Guard, Immigration and Customs Enforcement and Customs and Border Protection.

The latest: The Army moved 1,600 soldiers from out of state into D.C. area, the Defense Department confirmed in a statement Tuesday. Protesters were still out en masse after curfews began in cities including Washington, D.C., New York City, Los Angeles and Portland.

Primary elections test impact of protests, coronavirus on voting

Election official at a polling place at McKinley Technology High School in Washington, D.C. Photo: Drew Angerer/Getty Images

In the midst of a global pandemic and national protests over the death of George Floyd, eight states and the District of Columbia held primary elections on Tuesday.

Why it matters: Joe Biden, the presumptive Democratic nominee, needs to win 425 of the 479 delegates up for grabs in order to officially clinch the nomination. There are a number of key down-ballot races throughout the country as well, including a primary in Iowa that could determine the fate of Rep. Steve King (R-Iowa).

Iowa Rep. Steve King defeated in GOP primary

Rep. Steve King. Photo: Alex Wroblewski/Getty Images

State Sen. Randy Feenstra defeated incumbent Rep. Steve King in Tuesday's Republican primary for Iowa's 4th congressional district, according to the Cook Political Report.

Why it matters: King's history of racist remarks has made him one of the most controversial politicians in the country and a pariah within the Republican Party.