North Korean hackers hijack Google’s Find Hub to find and wipe target devices

  • KONNI hackers use KakaoTalk to deliver malware and harvest account credentials from victims
  • Attackers exploit Google Find Hub to remotely wipe Android devices and evade detection
  • Compromised PCs spread malware to contacts while mobile devices are repeatedly factory reset

North Korean threat actors with ties to the government were seen resetting target Android devices to factory settings to cover their tracks.

Researchers from Genians said they saw these attacks in the wild, targeting primarily individuals in South Korea, carried out by a group called KONNI (named after a remote access tool it is using)

The researchers say KONNI has “overlapping targets and infrastructure” with both Kimsuky, and APT37, known North Korean state-sponsored actors.

Wiping the device

The attack starts on KakaoTalk messenger, one of the most popular instant chat messaging platforms in the country, where KONNI’s agents impersonate trusted entities like the National Tax Service, or the police.

During the conversation, they send a digitally signed MSI file (or a ZIP archive with it) which, if the victim runs it, launches a script that ultimately downloads different malware modules, including RemcosRAT, QuasarRAT, and RftRAT.

These RATs harvest all sorts of information from the compromised device, including Google and Naver account credentials which are then used to log into the victim’s Google account.

From there, they access Google Find Hub, a built-in tool that lets users remotely locate, lock, or wipe their devices, and use it not only to view all other registered Android devices, but also to track the victim’s location.

When they see the victim out and about, and unable to quickly address an attack, they send remote factor reset commands to all devices, erasing data, disabling alerts, and disconnecting the victim from the KakaoTalk PC sessions. The wipe is done three times.

With the mobile device wiped but the KakaoTalk PC session still active, the hackers use the compromised computer to send malicious files to the victim’s contacts, spreading the infections further.

The motive behind the attack is unknown at the time, but state-sponsored threat actors are usually engaged in cyber-espionage and disruption.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’

Dave Eggers attends the "The Turning Point: To Be Destroyed" premiere. | Image: John Lamparski/Getty Images for Tribeca Festival Last year, Sam Altman invited author...

YouTube picture-in-picture (PiP) mode is broken on iPhone, Android

YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app. Read more @ 9to5google

Galaxy Watch 9 is ‘Powered by Snapdragon Wear Elite,’ leaked images confirm [Gallery]

As expected, Samsung is switching its new Galaxy Watch 9 over to a Qualcomm chip, the Snapdragon Wear Elite, as some new images confirm....

Google is open-sourcing its 3D emoji

Now, if you want to, you can use Google's 3D emoji in your own creations. The company shared some details about how it went...

Google might not kneecap the Pixel 11a with an old processor

The Pixel 10a shipped with a last gen processor. | Photo: Dominic Preston / The Verge Mystic Leaks suggests that the Pixel 11a will return...

Sony’s flagship RGB LED TV is incredible

Sony’s flagship Bravia 9 II is the best RGB LED TV I’ve seen this year. The Sony Bravia 9 II is the most anticipated new...

Surprise! Facial recognition smart locks are actually good

Facial recognition smart locks are here; now you can unlock your door the same way you unlock your phone. | Photo by Jennifer Pattison...

The Guardian’s Carter Sherman fondly remembers being terrified by Ocarina of Time

Carter, there’s a couch RIGHT THERE. | Image: Carter Sherman has been covering sex, gender, and the complex personal and national politics that accompany them...

GoPro’s discounted Max 2 bundle includes $100 worth of accessories

The GoPro Max2 can use your earbuds as a microphone over Bluetooth. A 360-degree camera is a great way to ensure you capture every bit...

Pixelated 108: Rerun of a rerun

Welcome to Pixelated episode 108. This week, Damien, Abner, and Will briefly dive into Google and Epic’s decision to wrap up their legal battle...