Share

North Korean hackers hijack computers to mine cryptocurrencies

accreditation

Seoul - North Korean hackers are hijacking computers to mine cryptocurrencies as the regime in Pyongyang widens its hunt for cash under tougher international sanctions.

A hacking unit called Andariel seized a server at a South Korean company in the summer of 2017 and used it to mine about 70 Monero coins - worth about $25 000 as of December 29 - according to Kwak Kyoung-ju, who leads a hacking analysis team at the South Korean government-backed Financial Security Institute.

The case underscores the increasing appetite from cyber-attackers for digital currencies that are becoming a source of income for the Kim Jong Un regime. North Korea is accelerating its pursuit of cash abroad as the world tightens its stranglehold on its conventional sources of money with sanctions cutting oil supplies and other trade bans.

“Andariel is going after anything that generates cash these days,” said Kwak. “Dust gathered over time builds a mountain.”

The hackers may have seized other computers to mine cryptocurrencies and appear to prefer Monero because the currency is more focused on privacy and easier to hide and launder than bitcoin, Kwak said, citing the analysis of the server. Andariel was able to take control of the server undetected by its operator, he said.

Mining money

A cryptocurrency can be earned if a complex mathematical problem is solved, but it requires high-powered computers that often only corporations can afford. Not every company spends as much on protecting their computers from hackers. Yapian, the owner of bitcoin exchange Youbit, said in December it would close after getting breached.

Like bitcoin, Monero uses a network of miners to verify its trades. But it mixes multiple transactions to make it harder to trace the origin of funds, and adopts “dual-key stealth” addresses that make it difficult to pinpoint recipients.

South Korean investigators are looking at North Korea among their suspects. The country’s hackers are increasing attacks on cryptocurrency exchanges in Seoul, security researcher FireEye said in September. 

The US has also blamed North Korea recently for the WannaCry ransomware attack that affected hundreds of thousands of computers globally in 2017.

READ: Here's how to protect yourself against WannaCry and other malware

Hackers demanded bitcoin in exchange for unlocking the files they had coded with malware. North Korea denies any role in cyber crimes.

The majority of attacks from North Korean hackers in the past year have focused on financial gain rather than government secrets, according to researchers dealing with them. The shift of focus may accelerate this year as the UN is stepping up its efforts to cut the flow of funds used by the regime to fuel its nuclear arms development.

* Sign up to Fin24's top news in your inbox: SUBSCRIBE TO FIN24 NEWSLETTER

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.16
+0.3%
Rand - Pound
23.95
+0.0%
Rand - Euro
20.53
+0.1%
Rand - Aus dollar
12.49
-0.0%
Rand - Yen
0.12
+0.5%
Platinum
917.20
+0.6%
Palladium
1,009.00
+0.4%
Gold
2,322.34
+0.3%
Silver
27.34
+0.7%
Brent Crude
88.02
-0.5%
Top 40
68,735
+0.2%
All Share
74,655
+0.2%
Resource 10
61,869
+2.4%
Industrial 25
103,378
-0.6%
Financial 15
15,845
+0.1%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders