US imposes sanctions on North Korean hacking groups blamed for global attacks

Published September 13, 2019
The United States Treasury names the groups as Lazarus Group, Bluenoroff, and Andariel. — AFP/File
The United States Treasury names the groups as Lazarus Group, Bluenoroff, and Andariel. — AFP/File

The United States Treasury on Friday announced sanctions on three North Korean hacking groups it said were involved in the “WannaCry” ransomware attacks and hacking of international banks and customer accounts.

It named the groups as Lazarus Group, Bluenoroff, and Andariel and said they were controlled by the RGB, North Korea's primary intelligence bureau, which is already subject to US and United Nations sanctions.

The action blocks any US-related assets of the groups and prohibits dealings with them. The Treasury statement said any foreign financial institution that knowingly facilitated significant transactions or services for them could also be subject to sanctions.

“Treasury is taking action against North Korean hacking groups that have been perpetrating cyber attacks to support illicit weapon and missile programmes,” said Sigal Mandelker, Treasury under secretary for Terrorism and Financial Intelligence.

“We will continue to enforce existing US and UN sanctions against North Korea and work with the international community to improve cyber security of financial networks.”

The US has been attempting to restart talks with North Korea, aimed at pressing the country to give up its nuclear weapons. The talks have been stalled over North Korean demands for concessions, including sanctions relief.

Earlier this month, North Korea denied UN allegations it had obtained $2 billion through cyber attacks on banks and cryptocurrency exchanges, and accused the US of spreading rumors.

The US Treasury statement said Lazarus Group was involved in the WannaCry ransomware attack that the US, Australia, Canada, New Zealand and the United Kingdom publicly attributed to North Korea in December 2017.

It said WannaCry affected at least 150 countries and shut down about 300,000 computers, including many in Britain's National Health Service (NHS). The NHS attack led to the cancellation of more than 19,000 appointments and ultimately cost the service over $112 million, the biggest known ransomware attack in history.

The US Treasury said Lazarus Group was also directly responsible for 2014 cyber attacks on Sony Pictures Entertainment.

The statement cited industry and press reporting as saying that by 2018, Bluenoroff had attempted to steal over $1.1bn from financial institutions and successfully carried out operations against banks in Bangladesh, India, Mexico, Pakistan, Philippines, South Korea, Taiwan, Turkey, Chile, and Vietnam.

It said Bluenoroff worked with the Lazarus Group to steal approximately $80mn from the Central Bank of Bangladesh's New York Federal Reserve account.

Andariel, meanwhile, was observed by cyber security firms attempting to steal bank card information by hacking into ATMs to withdraw cash or steal customer information to later sell on the black market, the statement said.

Andariel was also responsible for developing and creating unique malware to hack into online poker and gambling sites and, according to industry and press reporting, targeted the South Korea government military in an effort to gather intelligence, it said.

Opinion

Editorial

Weathering the storm
Updated 29 Apr, 2024

Weathering the storm

Let 2024 be the year when we all proactively ensure that our communities are safeguarded and that the future is secure against the inevitable next storm.
Afghan repatriation
29 Apr, 2024

Afghan repatriation

COMPARED to the roughshod manner in which the caretaker set-up dealt with the issue, the elected government seems a...
Trying harder
29 Apr, 2024

Trying harder

IT is a relief that Pakistan managed to salvage some pride. Pakistan had taken the lead, then fell behind before...
Return to the helm
Updated 28 Apr, 2024

Return to the helm

With Nawaz Sharif as PML-N president, will we see more grievances being aired?
Unvaxxed & vulnerable
Updated 28 Apr, 2024

Unvaxxed & vulnerable

Even deadly mosquito-borne illnesses like dengue and malaria have vaccines, but they are virtually unheard of in Pakistan.
Gaza’s hell
Updated 28 Apr, 2024

Gaza’s hell

Perhaps Western ‘statesmen’ may moderate their policies if a significant percentage of voters punish them at the ballot box.