Microsoft takes down 50 North Korean hacking sites

Microsoft takes down 50 North Korean hacking sites
(Image credit: TheDigitalArtist / Pixabay)

Microsoft has successfully launched a court action to take control of fifty domains used for spear phishing attacks.

These attacks apparently came from a hacking group affiliated with North Korea, and collected user account details in order to both steal data as well as upload malware in an attempt to infect IT systems.

Spear phishing

The phishing emails were targeted at employees of governments, international agencies, as well as university staff, mostly based in the US, Japan, and North Korea. The spoof emails claimed that the user’s account was compromised, advising them to login to change their account details.

Of course, the links went to domain names that attempted to look official in order to record the user account details. Once inputted, hackers could use this login information to access the user’s official account. From there, they would not just access and copy user information, but also install malware in an attempt to infiltrate any IT systems the user had access to.

Additionally, the hackers were able to set up a command to copy any new emails to the user without the user realizing, even when the account password had been changed.

According to Microsoft, the court action allowed Microsoft to take control of the fifty domain names used in the attack.

While presented as a victory against cyberattacks, domain names are cheap and it would be easy for the hacking group to simply copy their phishing attacks onto a new set of domains.

Additionally, users are reminded that in the event of ever receiving an email claiming your account details have been compromise, DON’T click on the links in the email, but instead visit the main website directly in order to avoid what is one of the most common yet easiest to avoid web attacks.

Via ZDnet.

Brian Turner

Brian has over 30 years publishing experience as a writer and editor across a range of computing, technology, and marketing titles. He has been interviewed multiple times for the BBC and been a speaker at international conferences. His specialty on techradar is Software as a Service (SaaS) applications, covering everything from office suites to IT service tools. He is also a science fiction and fantasy author, published as Brian G Turner.

Latest in Security
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
A digital representation of blockchain.
Malicious npm packages use devious backdoors to target users
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
Latest in News
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Nintendo Switch 2
The Nintendo Switch 2 pre-order date has seemingly been confirmed by Best Buy Canada – here's when you'll be able to order yours
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long