{"id":41176,"date":"2022-07-27T08:40:00","date_gmt":"2022-07-27T08:40:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/41176"},"modified":"2022-07-27T08:40:00","modified_gmt":"2022-07-27T08:40:00","slug":"us-doubles-bounty-on-lazarus-cyber-crime-group-to-10m","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=41176","title":{"rendered":"US doubles bounty on Lazarus cyber crime group to $10m"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/us-doubles-bounty-on-lazarus-cyber-crime-group-to-10m.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The US State Department has doubled its reward for information on cyber threat actors located in, or linked to, North Korea from $5m to $10m (\u00a34.2m to \u00a38.3m), including the likes of Andariel, Bluenoroff, Kimsuky, and the notorious Lazarus syndicate, the group implicated in <a href=\"https:\/\/www.computerweekly.com\/news\/252496494\/North-Korean-Lazarus-Group-hackers-indicted-in-US\">the 2017 WannaCry incident<\/a> and a spate of other attacks.<\/p>\n<p>In a new notice posted to Twitter, the <a href=\"https:\/\/rewardsforjustice.net\/\">Rewards for Justice<\/a> programme \u2013 which was established in the 1980s to offer bounties for information on terrorism and, latterly, cyber crime \u2013 invited anyone with information on these groups to contact it through its dark web-based Tor tip line.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">REWARD! Up to $10M for information on DPRK-linked malicious <a href=\"https:\/\/twitter.com\/hashtag\/cyber?src=hash&amp;ref_src=twsrc%5Etfw\">#cyber<\/a> activity &amp; <a href=\"https:\/\/twitter.com\/hashtag\/cyberthreat?src=hash&amp;ref_src=twsrc%5Etfw\">#cyberthreat<\/a> actors. <\/p>\n<p>Got a tip on the Lazarus Group, Kimsuky, Bluenoroff, Andariel, or others? Send it to RFJ via our TOR-based tip line. <a href=\"https:\/\/t.co\/oZCKNHU3fY\">https:\/\/t.co\/oZCKNHU3fY<\/a> <a href=\"https:\/\/t.co\/ONKHXwWiV1\">pic.twitter.com\/ONKHXwWiV1<\/a><\/p>\n<p> \u2014 Rewards for Justice (@RFJ_USA) <a href=\"https:\/\/twitter.com\/RFJ_USA\/status\/1551915545288663041?ref_src=twsrc%5Etfw\">July 26, 2022<\/a>\n<\/p><\/blockquote>\n<p>The State Department said North Korean threat actors were targeting US critical infrastructure with disruptive cyber attacks in violation of the Computer Fraud and Abuse Act, as well as targeting financial institutions \u2013 <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252518378\/Axie-Infinity-hack-highlights-DPRK-cryptocurrency-heists\">including cryptocurrency exchanges<\/a> \u2013 and businesses to steal funds in support of North Korea\u2019s nuclear and ballistic missile programmes, in contravention of sanctions against the regime.<\/p>\n<p>Kevin Bocek, vice-president of security strategy and threat intelligence at <a href=\"https:\/\/www.venafi.com\/\">Venafi<\/a>, a specialist in machine identity management, said the doubling of the reward showed how much of a threat North Korean actors have become in the international cyber crime sphere.<\/p>\n<p><strong>\u201c<\/strong><a href=\"https:\/\/www.venafi.com\/blog\/north-korean-cyberattacks-can-inspire-other-rogue-nations\">Our research<\/a> shows that the proceeds of cyber criminal activities from infamous groups such as Lazarus and APT38 \u2013 which are both named by the US State Department \u2013 are being used to circumvent international sanctions in North Korea,\u201d said Bocek.<\/p>\n<p>\u201cThis money is being funneled directly into weapons programmes and cyber crime has become an essential cog in the ongoing survival of Kim Jong Un\u2019s dictatorship. Worryingly, this blueprint is also being mimicked by other rogue states. So, cutting North Korean cyber crime off at the source is essential to the national security of the US and its allies.\u201d<\/p>\n<p>He added: \u201cGovernments and businesses must act together and share intelligence on these attacks to build knowledge on the importance of machine identities in security, otherwise we\u2019ll continue to see North Korean threat actors thrive.\u201d<\/p>\n<p>The latest call to action comes a week after the US Justice <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-seizes-and-forfeits-approximately-500000-north-korean-ransomware-actors\">Department seized about $500,000 worth of cryptocurrency<\/a> from another North Korean cyber criminal operation going by the name of Maui.<\/p>\n<p>The sums included ransomware payments made by two healthcare organisations, both of which are being returned to the victims.<\/p>\n<p>According to court documents, the action was made possible because the first victim, an unnamed organisation based in the state of Kansas, promptly notified the FBI of the incident, admitted it had had to make a payment (not advised) to recover access to its systems, and fully cooperated with the subsequent investigation.<\/p>\n<p>In the course of its probe, the FBI was able to identify the Maui ransomware \u2013 which had not been seen before \u2013 and could easily trace the payment to a China-based money launderer. The subsequent seizure, made in April, led the investigators to other accounts and a second victim, another healthcare organisation from the state of Colorado.<\/p>\n<p>\u201cReporting cyber incidents to law enforcement and cooperating with investigations not only protects the United States, it is also good business,\u201d said assistant attorney general Matthew Olsen of the Justice Department\u2019s National Security Division.<\/p>\n<p>\u201cThe reimbursement to these victims of the ransom shows why it pays to work with law enforcement.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US State Department has doubled its reward for information on cyber threat actors located in, or linked to, North Korea from $5m to $10m (\u00a34.2m to \u00a38.3m), including the likes of Andariel, Bluenoroff, Kimsuky, and the notorious Lazarus syndicate, the group implicated in the 2017 WannaCry incident and a spate of other attacks. In [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":41177,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-41176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41176"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41176\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/41177"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}