North Korea was behind the foiled hack into the heart of Israel’s defense establishment
The attack is part of an ongoing campaign by the notorious Lazarus Group trying to steal data and money in the service of Pyongyang
09:5213.08.20
A cyber attack targeting Israeli defense industry employees which was foiled by the ministry of defense was found to be part of an ongoing offensive campaign by the Lazarus Group. The group’s activities are linked to the North Korean government and many cyber experts have for years been treating it as a branch of the rogue state’s spy agency. According to people in the Israeli cyber industry who spoke to Calcalist on condition of anonymity, the group has been conducting its campaign for the last two years and its targets include states in Western Europe, Chile, and Asian countries.
According to the defense ministry, which successfully thwarted the campaign, the attackers approached employees in various defense companies through LinkedIn offering tempting job opportunities with the aim of hacking into their computer networks and gathering sensitive information.
The hackers, according to the ministry, used various techniques to entice their potential victims, including "social engineering" and impersonating human resources executives in multinational companies. “For the purpose of the attack, the hackers used legitimate websites of other companies and industries, without the companies’ knowledge,” the ministry said in a statement.

Israel's Ministry of Defense building in Tel Aviv. Photo: Bar Tal Shalomצילום: בר טל שלום
In recent years several weaknesses in LinkedIn’s security mechanisms were revealed, which were in turn remedied. It is not clear if the current campaign took advantage of those weaknesses or newer ones that have yet to have been fixed. According to ESET’s cyber experts, the files were transferred directly via LinkedIn or via emails containing OneDrive links. The hackers created customized email accounts that matched their fake LinkedIn posts.
Related articles

LinkedIn's mobile app. Photo: Shutterstockצילום: שאטרסטוק
The company said that in addition to the spying activities, ESET researchers also found evidence that the hackers attempted to use the hacked accounts in order to steal money from other companies.

