North Korean hackers breached top Russian missile maker

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Russia and North Korea may reprotedly be allies on paper, but in the real world, this may not be as concrete, as two North Korean state-sponsored threat actors have been found targeting an important Russian missile engineering company.

Cybersecurity researchers from SentinelOne discovered two groups - StarCruft and Lazarus Group, targeting NPO Mashinostroyenia. StarCruft managed to compromised “sensitive internal IT infrastructure”, including an email server. 

Lazarus, on the other hand, used a Windows backdoor known as OpenCarrot. The former is under the direct command of the Ministry of State Security, while the latter answers to the Reconnaissance General Bureau (RGB), the country’s main foreign intelligence service.

OpenCarrot

OpenCarrot is a versatile piece of malware, the researchers further explained, capable of “full compromise”. It sports 25 different commands, allowing the threat actors to spy on its victims, edit file systems, and operate multiple mechanisms of communication. 

"With a wide range of supported functionality, OpenCarrot enables full compromise of infected machines, as well as the coordination of multiple infections across a local network," said security researchers Tom Hegel and Aleksandar Milenkoski.

In hindsight, the choice of target isn’t that surprising, knowing that North Korea is investing heavy resources into developing its highly controversial missile program which, among other things, resulted in countless international sanctions. NPO Mashinostroyeniya, on the other hand, is a rocket design bureau based in Reutov, the media say. It was blacklisted by the U.S. Department of Treasury back in 2014, due to "Russia's continued attempts to destabilize eastern Ukraine and its ongoing occupation of Crimea."

This is one of the rare recorded examples of allies targeting allies through cyber-warfare, in order to advance their strategic goals. Time describes the North Korean government as being “hell-bent” on developing its nuclear program and missile capabilities for over 60 years now.

Via: The Hacker News

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean Lazarus hackers are targeting nuclear workers
Image depicting a hand on a scanner
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
North Korean Lazarus hackers launch large-scale cyberattack by cloning open source software
A digital representation of a lock
Looking for a new job? Watch out you don't fall for this new malware scam
North Korean flag with a hooded hacker
North Korean hackers are posing as software development recruiters to target freelancers
Hacker raise hands up to control computer coding, 3D rendering.
North Korean hackers target South Korea with Internet Explorer vulnerabilities to deploy RokRAT malware
Latest in Pro
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
AOC Graphic Pro U32U3CV during our review
I reviewed the AOC Graphic Pro U32U3CV and it's a staggeringly pro-grade monitor for the price
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day