Skip to content
General

Microsoft takes action against hackers from North Korea

By Rajiv MenonKorea
1 min read
Microsoft Store Front
Microsoft Store Front
In this article (5)

In a recent blog post on the Microsoft website, the company detailed steps it has taken to take legal action against a cybercrime group and protect customer information.

The security threat came from a group known as Thallium, which reportedly is based in North Korea. The group used a technique called ‘spear phishing’ to steal sensitive information, in which the group replicated the form and design of a genuine Microsoft security email while embedding dangerous links that, when clicked, would allow the group to extract sensitive account information.

According to the Washington-based firm, the threat was focused on users affiliated with the government, universities, human rights groups, and other organizations, with most of the victims concentrated in the US, Japan, and South Korea.

The particularly dangerous part of the scheme is that once Thallium takes control of an account in this way, it is possible for it to set up automatic forwarding in a way that gives the group access to any new emails the victim receives, even after the password is reset.

The cybercrime group was able to use this method by using domains such as “rniscoroft.com”, which uses the combination of ‘r’ and ‘n’ to facsimile the authentic Microsoft domain. Thus, the Windows company filed a court case and was able to take control of 50 such domains in order to stop the attacks.

Microsoft states that this is the fourth nation-state cybercrime group they have taken legal action against. The security threat has hopefully now been neutralized, but users are advised to be wary of suspicious emails and always check carefully before clicking email links or entering sensitive information.

Questions & Answers

Q.

Which specific cybercrime group was Microsoft taking action against in this instance?

A.

Microsoft initiated legal action against a group identified as Thallium. This group, reportedly based in North Korea, was responsible for the cyberattacks detailed in the company's blog post.

Q.

What method did the cybercrime group use to obtain sensitive user information?

A.

The group employed a technique called 'spear phishing'. They replicated genuine Microsoft security emails, embedding dangerous links that, when clicked, allowed them to extract sensitive account details.

Q.

What types of users were primarily targeted by the Thallium group?

A.

The threat focused on users affiliated with government, universities, and human rights groups. Most victims were concentrated in the US, Japan, and South Korea, according to the Washington-based firm.

Q.

How did Microsoft address the cybercrime group's use of deceptive domains?

A.

Microsoft filed a court case to combat the deceptive domains. This legal action allowed the company to take control of 50 such domains, thereby stopping the attacks.

Reader pulse

Is Microsoft's legal domain seizure an effective long-term deterrent?

22,719 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready