North Korean cyber spies tricking foreign experts into writing research for them | The Business Standard
Skip to main content
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Monday
May 19, 2025

Sign In
Subscribe
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
MONDAY, MAY 19, 2025
North Korean cyber spies tricking foreign experts into writing research for them

World+Biz

Reuters
12 December, 2022, 03:00 pm
Last modified: 12 December, 2022, 03:08 pm

Related News

  • North Korea's Kim Jong Un oversees air drills, calls for stepped-up war preparation
  • North Korean leader Kim Jong Un says participation in Russia-Ukraine war justified: KCNA
  • North Korea's Kim visits Russian embassy as his generals meet Putin
  • North Korea's Kim visits tank factory, touts progress in Korean-style tanks
  • North Korea conducts first test firing of its new warship's weapons system

North Korean cyber spies tricking foreign experts into writing research for them

Reuters
12 December, 2022, 03:00 pm
Last modified: 12 December, 2022, 03:08 pm
FILE PHOTO: People visit the the statues of North Korea's founder Kim Il Sung and late leader Kim Jong Il on the 74th anniversary of North Korea's founding, in Pyongyang, North Korea in this photo released by North Korea's Korean Central News Agency (KCNA) September 10, 2022. KCNA via REUTERS
FILE PHOTO: People visit the the statues of North Korea's founder Kim Il Sung and late leader Kim Jong Il on the 74th anniversary of North Korea's founding, in Pyongyang, North Korea in this photo released by North Korea's Korean Central News Agency (KCNA) September 10, 2022. KCNA via REUTERS

When Daniel DePetris, a US-based foreign affairs analyst, received an email in October from the director of the 38 North think-tank commissioning an article, it seemed to be business as usual.

It wasn't.

The sender was actually a suspected North Korean spy seeking information, according to those involved and three cybersecurity researchers.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

Instead of infecting his computer and stealing sensitive data, as hackers typically do, the sender appeared to be trying to elicit his thoughts on North Korean security issues by pretending to be 38 North director Jenny Town.

"I realized it wasn't legit once I contacted the person with follow up questions and found out there was, in fact, no request that was made, and that this person was also a target," DePetris told Reuters, referring to Town. "So I figured out pretty quickly this was a widespread campaign."

The email is part of a new and previously unreported campaign by a suspected North Korean hacking group, according to the cybersecurity experts, five targeted individuals and emails reviewed by Reuters.

The hacking group, which researchers dubbed Thallium or Kimsuky, among other names, has long used "spear-phishing" emails that trick targets into giving up passwords or clicking attachments or links that load malware. Now, however, it also appears to simply ask researchers or other experts to offer opinions or write reports.

According to emails reviewed by Reuters, among the other issues raised were China's reaction in the event of a new nuclear test; and whether a "quieter" approach to North Korean "aggression" might be warranted.

"The attackers are having a ton of success with this very, very simple method," said James Elliott of the Microsoft Threat Intelligence Center (MSTIC), who added that the new tactic first emerged in January. "The attackers have completely changed the process."

MSTIC said it had identified "multiple" North Korea experts who have provided information to a Thallium attacker account.

The experts and analysts targeted in the campaign are influential in shaping international public opinion and foreign governments' policy toward North Korea, the cybersecurity researchers said.

A 2020 report by US government cybersecurity agencies said Thallium has been operating since 2012 and "is most likely tasked by the North Korean regime with a global intelligence gathering mission."

Thallium has historically targeted government employees, think tanks, academics, and human rights organisations, according to Microsoft.

"The attackers are getting the information directly from the horse's mouth, if you will, and they don't have to sit there and make interpretations because they're getting it directly from the expert," Elliot said.

NEW TACTICS

North Korean hackers are well-known for attacks netting millions of dollars, targeting Sony Pictures over a film seen as insulting to its leader, and stealing data from pharmaceutical and defence companies, foreign governments, and others.

North Korea's embassy in London did not respond to a request for comment, but it has denied being involved in cyber crime.

In other attacks, Thallium and other hackers have spent weeks or months developing trust with a target before sending malicious software, said Saher Naumaan, principal threat intelligence analyst at BAE Systems Applied Intelligence.

But according to Microsoft, the group now also engages with experts in some cases without ever sending malicious files or links even after the victims respond.

This tactic can be quicker than hacking someone's account and wading through their emails, bypasses traditional technical security programmes that would scan and flag a message with malicious elements, and allows the spies direct access to the experts' thinking, Elliot said.

"For us as defenders, it's really, really hard to stop these emails," he said, adding that in most cases it comes down to the recipient being able to figure it out.

Town said some messages purporting to be from her had used an email address that ended in ".live" rather than her official account, which ends in ".org", but had copied her full signature line.

In one case, she said, she was involved in a surreal email exchange in which the suspected attacker, posing as her, included her in a reply.

DePetris, a fellow with Defense Priorities and a columnist for several newspapers, said the emails he has received were written as if a researcher were asking for a paper submission or comments on a draft.

"They were quite sophisticated, with think tank logos attached to the correspondence to make it look as if the inquiry is legitimate," he said.

About three weeks after receiving the faked email from 38 North, a separate hacker impersonated him, emailing other people to look at a draft, DePetris said.

That email, which DePetris shared with Reuters, offers $300 for reviewing a manuscript about North Korea's nuclear programme and asks for recommendations for other possible reviewers. Elliot said the hackers never paid anyone for their research or responses, and would never intend to.

GATHERING INFORMATION

Impersonation is a common method for spies around the world, but as North Korea's isolation has deepened under sanctions and the pandemic, Western intelligence agencies believe Pyongyang has become particularly reliant on cyber campaigns, one security source in Seoul told Reuters, speaking condition of anonymity to discuss intelligence matters.

In a March 2022 report, a panel of experts that investigates North Korea's UN sanctions evasions listed Thallium's efforts as among activities that "constitute espionage intended to inform and assist" the country's sanctions avoidance.

Town said in some cases, the attackers have commissioned papers, and analysts had provided full reports or manuscript reviews before realising what had happened.

DePetris said the hackers asked him about issues he was already working on, including Japan's response to North Korea's military activities.

Another email, purporting to be a reporter from Japan's Kyodo News, asked a 38 North staffer how they thought the war in Ukraine factored in North Korea's thinking, and posed questions about US, Chinese, and Russian policies.

"One can only surmise that the North Koreans are trying to get candid views from think tankers in order to better understand US policy on the North and where it may be going," DePetris said.

north korea / Spy / cyber spies

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Infograph: TBS
    New law planned to protect insurance clients as 6 firms embezzle Tk3,736cr
  • Representational image of a self-employed individual. Photo: Unsplash
    Tk100cr fund for youth self-employment on the cards
  • Protesters block army vehicles inside the National Press Club in Dhaka on 18 May 2025. Photo: TBS
    Army assures fair review of ex-armed forces members’ demands under existing rules: ISPR

MOST VIEWED

  • Illustration: Ashrafun Naher Ananna/TBS
    World’s top universities outside United States 2025
  • Infograph: TBS
    US-Bangladesh FTA talks begin, RMG may see major boost
  • Representational image. Photo: TBS
    India halts import of Bangladeshi garments, processed foods via land ports
  • Nusraat Faria Mazhar. Photo: Noor A Alam/TBS
    Actress Nusraat Faria detained at Dhaka airport over attempted murder case
  • Infographic: TBS
    Nationwide elevated highways in the works to boost mobility, minimise land use
  • Employees of the now-dissolved NBR hold a protest programme in front of the revenue board's HQ on 13 May. Photo: Jahir Rayhan/TBS
    Govt looks for ways to resolve NBR deadlock

Related News

  • North Korea's Kim Jong Un oversees air drills, calls for stepped-up war preparation
  • North Korean leader Kim Jong Un says participation in Russia-Ukraine war justified: KCNA
  • North Korea's Kim visits Russian embassy as his generals meet Putin
  • North Korea's Kim visits tank factory, touts progress in Korean-style tanks
  • North Korea conducts first test firing of its new warship's weapons system

Features

PHOTO: Collected

Helmet Hunt: Top 5 half-face helmets that meet international safety standards

16h | Wheels
Photo: Collected

Simple accessories to extend the life of your luggage

17h | Brands
With a growing population, the main areas of Rajshahi city are now often clogged with traffic. Photo: Mahmud Jami

Once a ‘green city’, Rajshahi now struggling to breathe

1d | Panorama
Illustration: TBS

Cassettes, cards, and a contactless future: NFC’s expanding role in Bangladesh

2d | Panorama

More Videos from TBS

What is the source of power of billionaire global Muslim leader Agha Khan?

What is the source of power of billionaire global Muslim leader Agha Khan?

9h | Others
News of The Day, 18 MAY 2025

News of The Day, 18 MAY 2025

12h | TBS News of the day
Arab League allies in Baghdad for Gaza

Arab League allies in Baghdad for Gaza

10h | TBS World
India's ban on land-based imports of goods; is this a countermeasure?

India's ban on land-based imports of goods; is this a countermeasure?

11h | Podcast
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net