AIRLINK 196.38 Increased By ▲ 4.54 (2.37%)
BOP 10.11 Increased By ▲ 0.24 (2.43%)
CNERGY 7.75 Increased By ▲ 0.08 (1.04%)
FCCL 38.10 Increased By ▲ 0.24 (0.63%)
FFL 15.74 Decreased By ▼ -0.02 (-0.13%)
FLYNG 24.54 Decreased By ▼ -0.77 (-3.04%)
HUBC 130.38 Increased By ▲ 0.21 (0.16%)
HUMNL 13.73 Increased By ▲ 0.14 (1.03%)
KEL 4.60 Decreased By ▼ -0.07 (-1.5%)
KOSM 6.19 Decreased By ▼ -0.02 (-0.32%)
MLCF 44.85 Increased By ▲ 0.56 (1.26%)
OGDC 206.51 Decreased By ▼ -0.36 (-0.17%)
PACE 6.58 Increased By ▲ 0.02 (0.3%)
PAEL 39.77 Decreased By ▼ -0.78 (-1.92%)
PIAHCLA 17.20 Decreased By ▼ -0.39 (-2.22%)
PIBTL 7.99 Decreased By ▼ -0.08 (-0.99%)
POWER 9.20 Decreased By ▼ -0.04 (-0.43%)
PPL 178.91 Increased By ▲ 0.35 (0.2%)
PRL 38.93 Decreased By ▼ -0.15 (-0.38%)
PTC 24.31 Increased By ▲ 0.17 (0.7%)
SEARL 109.27 Increased By ▲ 1.42 (1.32%)
SILK 1.00 Increased By ▲ 0.03 (3.09%)
SSGC 37.75 Decreased By ▼ -1.36 (-3.48%)
SYM 18.83 Decreased By ▼ -0.29 (-1.52%)
TELE 8.53 Decreased By ▼ -0.07 (-0.81%)
TPLP 12.14 Decreased By ▼ -0.23 (-1.86%)
TRG 64.76 Decreased By ▼ -1.25 (-1.89%)
WAVESAPP 12.11 Decreased By ▼ -0.67 (-5.24%)
WTL 1.64 Decreased By ▼ -0.06 (-3.53%)
YOUW 3.87 Decreased By ▼ -0.08 (-2.03%)
BR100 12,000 Increased By 69.2 (0.58%)
BR30 35,548 Decreased By -112 (-0.31%)
KSE100 114,256 Increased By 1049.3 (0.93%)
KSE30 35,870 Increased By 304.3 (0.86%)

Microsoft said Monday it obtained a court order allowing it to seize web domains used by North Korean hacking groups to launch cyberattacks on human rights activists, researchers and others.

The US technology giant said a federal court allowed it to take control of 50 domains operated by a group dubbed Thallium, which tricked online users by fraudulently using Microsoft brands and trademarks.

"This network was used to target victims and then compromise their online accounts, infect their computers, compromise the security of their networks and steal sensitive information," said Tom Burt, Microsoft's vice president for customer security and trust.

"Based on victim information, the targets included government employees, think tanks, university staff members, members of organizations focused on world peace and human rights, and individuals that work on nuclear proliferation issues. Most targets were based in the US, as well as Japan and South Korea."

Microsoft, which had been investigating the group through its Digital Crimes Unit and Threat Intelligence Center, said the hacking group sent spoofed emails that appeared to come from Microsoft which tricked users into revealing their login credentials, a technique known as spear phishing.

"By gathering information about the targeted individuals from social media, public personnel directories from organizations the individual is involved with and other public sources, Thallium is able to craft a personalized spear-phishing email in a way that gives the email credibility to the target," Burt said.

After getting the victim's credentials, the hackers can access emails, contact lists, calendar appointments and other data and often forwards any new emails to the attackers.

The hackers also used malicious software which can access other data on a victim's computer. An order from a US federal court in Virginia allowed Microsoft to take control of the domains, meaning "the sites can no longer be used to execute attacks," Burt said. Microsoft said this was the fourth nation-state group it has acted against and follows similar moves against operations from China, Russia and Iran, dubbed Barium, Strontium and Phosphorus, respectively.

Copyright Agence France-Presse, 2019

Comments

Comments are closed.