North Korean hackers pose as security firm to target researchers

A state-sponsored operation hiding inside a fake security firm
North Korean hackers created an entire fraudulent company to deceive researchers into downloading malicious files.
Mark

Why would North Korea spend this much effort targeting security researchers specifically? What's the payoff?

Mimi

Access. If you compromise a security researcher, you're inside their network, their tools, their communications with other researchers and companies. You get visibility into what vulnerabilities are being discovered, what exploits are being developed, what defenses are being built. That's intelligence.

Mark

So this isn't about stealing money or launching ransomware attacks?

Mimi

Not directly. This is about staying ahead of the curve. If you know what the security community is working on before it's public, you can patch your own systems or develop countermeasures. You can also identify zero-day vulnerabilities before they're disclosed.

Mark

The fake company angle—why not just keep using the fake profiles they had in January?

Mimi

Because those were burned. Google exposed them. Once researchers know to look for those accounts, they're useless. A full corporate front is harder to dismiss. It has a website, a domain, a team. It looks real enough that someone doing a quick background check might miss the fraud.

Mark

How do you even catch something like this if you're not Google with massive resources?

Mimi

You probably don't, honestly. That's the uncomfortable truth. Most researchers would never know they were being targeted unless someone like Google connected the dots and warned them. The attack relies on the fact that most people don't have the infrastructure to detect it.

Mark

What happens next? Does this operation just stop?

Mimi

No. Google added the website to Safe Browsing and reported the profiles, but the group will almost certainly rebrand and try again. They've shown they're willing to invest time and resources into this. The researchers being targeted need to be more skeptical about unsolicited collaboration requests, but that's a hard ask in a field built on open collaboration.

  • A North Korean hacking group has turned the cybersecurity community's own culture of collaboration into a weapon, exploiting the trust researchers extend to apparent peers.
  • The operatives built fake identities across Twitter, LinkedIn, and Keybase — complete with blogs, research videos, and professional engagement — before proposing joint projects that delivered malicious payloads.
  • By mid-March, the campaign escalated: a fully fabricated security company called SecuriElite appeared online, complete with a Turkish address, professional branding, and a PGP key link suspected of routing victims to browser exploits.
  • Impersonation reached into the corporate world, with fake profiles mimicking HR recruiters and employees of real firms like Trend Micro, making the deception harder to detect at a glance.
  • Google has flagged the site and reported fraudulent profiles to platforms, but analysts warn the group almost certainly holds additional exploits and will keep targeting the researchers meant to stop them.

In the quiet corridors where defenders of the digital world gather to share knowledge, a shadow has learned to wear their face. North Korean state-sponsored hackers, tracked by Google's Threat Analysis Group, constructed an elaborate false identity — a fake Turkish security firm called SecuriElite — to lure cybersecurity researchers into trusting them, then compromising their machines. The campaign, which evolved from scattered fake social media personas into a fully branded corporate front, reflects a sobering irony: those who study threats have become the most prized targets of one. Google moved swiftly to warn the community, but the group's sophistication suggests the hunt is far from over.

In late March, Google's Threat Analysis Group uncovered a new phase in a North Korean hacking campaign first documented in January — one that had quietly matured from fake social media profiles into a fully fabricated security company.

The group's method was patient and precise. Operatives built convincing personas on Twitter, LinkedIn, and Keybase, presenting themselves as fellow security researchers. They published blogs, shared apparent research, and cultivated genuine-seeming relationships within the community. Once trust was established, they would propose collaboration — and deliver either a malicious Visual Studio project or a blog post laced with browser exploits.

By March 17, the operation had taken a bolder shape. The group registered a domain and launched SecuriElite, a fictitious Turkish penetration testing and exploit development firm. The website was professionally designed, complete with fabricated employee profiles and, notably, a PGP public key link — a detail Google recognized as a potential gateway to browser-based compromise, consistent with the group's earlier tactics.

Supporting the fake firm was a fresh network of social media accounts impersonating researchers, recruiters, and in at least one case, an HR director at a company whose name closely echoed that of real security vendor Trend Micro.

Google's Adam Weidman announced the findings on March 31. The SecuriElite site was added to Safe Browsing and fraudulent profiles were reported to their respective platforms. Though no active malware had yet been observed on the site, Google flagged it as a precautionary measure.

The deeper concern was what the campaign's evolution implied. Moving from loose fake personas to a corporate front suggested commitment, not retreat. With likely access to multiple browser exploits — including those targeting Internet Explorer — the group appeared to be refining its approach to a community that, by the nature of its work, is both vigilant and uniquely exposed.

In late March, Google's security team uncovered a new chapter in an ongoing campaign by North Korean hackers to infiltrate the world of cybersecurity researchers. The group, previously documented by Google's Threat Analysis Group in January, had been caught red-handed running a coordinated social engineering operation across multiple platforms. Now they were trying something different: they had created an entirely fake security company.

The operation, which Google researchers began tracking in January, relied on a simple but effective playbook. North Korean operatives would establish fake profiles on Twitter, LinkedIn, and Keybase, posing as fellow security professionals. They would start blogs, share videos of supposed research work, and engage with legitimate researchers in the community. The goal was to build enough credibility to seem like genuine peers in the field. Once they had established rapport, they would propose collaboration on cybersecurity research—a request that would seem natural to someone working in that space.

But the collaboration came with a trap. The hackers would send victims a malicious Visual Studio project file, or direct them to a blog post embedded with browser exploits designed to compromise their machines. It was a straightforward attack: gain trust, deliver the payload, gain access. Google's Threat Analysis Group, which specializes in tracking advanced persistent threat groups, documented the entire scheme and attributed it to North Korean state-sponsored actors.

By late March, the group had evolved. On March 17, they registered a domain called SecularLight.com and launched what appeared to be a legitimate security firm called SecuriElite. According to the company's website, it was based in Turkey and offered penetration testing, software security assessments, and exploit development services—exactly the kind of work that would appeal to security researchers looking for partners or employment. The website included professional branding and a team section populated with fabricated profiles of supposed employees.

One detail stood out: the site included a PGP public key link. While PGP keys are standard security practice for encrypted communication, Google's team recognized the tactic. The North Korean group had used similar links before as entry points to pages hosting browser-based exploits. Researchers clicking the link would find themselves compromised.

The fake SecuriElite team was equipped with a fresh set of social media profiles across multiple platforms. These accounts impersonated security researchers, recruiters from legitimate cybersecurity firms, and in at least one case, someone claiming to be an HR director at a company with a name suspiciously similar to Trend Micro, a real security vendor. The impersonation was precise enough to fool someone scrolling through professional networks.

Google's Adam Weidman, who leads the Threat Analysis Group, announced the discovery on March 31. The company immediately reported all the fraudulent profiles to the social media platforms hosting them and added the SecuriElite website to Google Safe Browsing, its database of known malicious sites. At the time of the report, the website had not yet been observed serving active malware, but Google treated it as a precautionary measure.

What made the discovery significant was not just the new tactic, but what it suggested about the group's capabilities and intentions. Google's analysis indicated that the North Korean operatives likely had access to multiple browser exploits, including ones targeting Internet Explorer. The shift from scattered fake profiles to a full corporate front suggested they were doubling down on the strategy, not abandoning it. Researchers in the cybersecurity field—the very people tasked with defending against such attacks—had become a priority target for a state-sponsored hacking operation.

To build credibility and connect with security researchers, actors set up a research blog and several Twitter profiles to interact with potential targets.
— Google Threat Analysis Group
We have reported all social media profiles on platforms to allow them to take appropriate action and added the website to Google Safe Browsing as a precaution.
— Google Threat Analysis Group
Quieres la nota completa? Lee el original en Jimmys Post ↗
Contáctanos FAQ