{"id":35580,"date":"2020-06-17T16:02:51","date_gmt":"2020-06-17T16:02:51","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31304\/North-Koreas-State-Hackers-Caught-Engaging-In-BEC-Scams.html"},"modified":"2020-06-17T16:02:51","modified_gmt":"2020-06-17T16:02:51","slug":"north-koreas-state-hackers-caught-engaging-in-bec-scams","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/","title":{"rendered":"North Korea&#8217;s State Hackers Caught Engaging In BEC Scams"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2019\/08\/13\/874ba233-9e30-417b-ae47-e6062ead7bce\/north-korea-reportedly-stole-2b-in-wave-5d4d934316e22d00012a3ac5-1-aug-13-2019-12-43-01-poster.jpg\" class alt=\"north-korea-reportedly-stole-2b-in-wave-5d4d934316e22d00012a3ac5-1-aug-13-2019-12-43-01-poster.jpg\"><\/span><\/p>\n<div class=\"relatedContent alignRight\" readability=\"8.0321285140562\">\n<h3 class=\"heading\"><span class=\"int\">Special feature<\/span><\/h3>\n<div class=\"thumb\"><a href=\"https:\/\/www.zdnet.com\/topic\/cyberwar-and-the-future-of-cybersecurity\/\" data-omniture-track=\"moduleClick\" data-omniture-track-data=\"{&quot;moduleInfo&quot;: &quot;pinbox&quot;, &quot;pageType&quot;: &quot;article&quot;}\" data-vanity-rewritten=\"true\"><span class=\"img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2016\/09\/01\/fa215859-76c8-4ab7-8b55-56a42e0d8950\/resize\/220x165\/cf651a47272fd8abf79b87f4b45ba3c4\/09-2016-special-feature-cover-art.jpg\" class alt=\"Cyberwar and the Future of Cybersecurity\" height=\"165\" width=\"220\"><\/span><\/a><\/div>\n<p class=\"title\"><a href=\"https:\/\/www.zdnet.com\/topic\/cyberwar-and-the-future-of-cybersecurity\/\" data-omniture-track=\"moduleClick\" data-omniture-track-data=\"{&quot;moduleInfo&quot;: &quot;pinbox&quot;, &quot;pageType&quot;: &quot;article&quot;}\" data-vanity-rewritten=\"true\">Cyberwar and the Future of Cybersecurity<\/a><\/p>\n<p class=\"dek\">Today&#8217;s security threats have expanded in scope and seriousness. There can now be millions &#8212; or even billions &#8212; of dollars at risk when information security isn&#8217;t handled properly.<\/p>\n<p class=\"read-more\"><a href=\"https:\/\/www.zdnet.com\/topic\/cyberwar-and-the-future-of-cybersecurity\/\" data-omniture-track=\"moduleClick\" data-omniture-track-data=\"{&quot;moduleInfo&quot;: &quot;pinbox&quot;, &quot;pageType&quot;: &quot;article&quot;}\" data-vanity-rewritten=\"true\">Read More<\/a><\/p>\n<\/div>\n<p>At the <a href=\"https:\/\/www.esetvirtualworld.com\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">ESET Virtual World<\/a> security conference on Tuesday, security researchers from Slovak antivirus maker ESET have disclosed a new operation orchestrated by the Pyongyang regime&#8217;s infamous state-sponsored hacker crews.<\/p>\n<p>Codenamed &#8220;<strong>Operation In(ter)ception<\/strong>,&#8221; this campaign targeted victims for both cyber-espionage and financial theft.<\/p>\n<p>Speaking in a live stream to an audience of thousands, ESET security researcher Jean-Ian Boutin said the attacks have been carried out by members of the <a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/actor\/lazarus_group\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Lazarus Group<\/a> &#8212; codename given by security firms to North Korea&#8217;s biggest hacking unit, part of the country&#8217;s intelligence service.<\/p>\n<h3>Attacks targeted European aerospace and military companies<\/h3>\n<p>Boutin described how Lazarus members used LinkedIn job recruiter profiles and private messages to approach their targets. On the guise of conducting a job interview, victims were given archives to open and view files stored inside that allegedly contained salary and other information about their future jobs.<\/p>\n<p>The ESET researcher says these archives contained malware-infected files that allowed the attackers to gain an initial foothold on the victim&#8217;s computer.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/\" class=\"lazy\" alt=\"interception-scheme.png\" data-original=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/06\/17\/32d646c1-6485-4896-8d54-876246713271\/interception-scheme.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/06\/17\/32d646c1-6485-4896-8d54-876246713271\/interception-scheme.png\" class alt=\"interception-scheme.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: ESET<\/span> <\/p>\n<p>Boutin says that once a victim would be infected, the Lazarus hacker would stop the interviewing process, tell the victim they didn&#8217;t get the job, and proceed to delete the LinkedIn profile immediately after.<\/p>\n<p>But on the infected employee&#8217;s computer, the hackers would continue to operate using their initial foothold and expand their access inside the hacked company&#8217;s network.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>&#8220;We found that the attackers queried the AD (Active Directory) server to obtain the list of employees including administrator accounts, and subsequently performed password brute-force attacks on the administrator accounts,&#8221; Boutin said.<\/p>\n<p>ESET said that based on malware specific to &#8220;Operation In(ter)ception&#8221; they found, these attacks appear to have taken place between September and December 2019.<\/p>\n<p>Targets usually included employees working at European aerospace and military companies, most of which were approached with fake job offers at competing or higher-profile companies.<\/p>\n<h3>BEC scam attempts<\/h3>\n<p>But Boutin said that once hackers gathered all the intelligence and proprietary data files they needed from a hacked company, the intrusion didn&#8217;t stop there. Instead of erasing their footprints, the hackers moved on to attempting to scam the infected company&#8217;s business partners.<\/p>\n<p>Boutin said that Lazarus hackers rummaged through the hacked companies email inboxes and looked for unpaid invoices.<\/p>\n<p>&#8220;They followed up the conversation and urged the customer to pay<br \/>the invoice, however, to a different bank account than previously agreed,&#8221; the ESET team wrote in a report published today [<a href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2020\/06\/ESET_Operation_Interception.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">PDF<\/a>].<\/p>\n<p>The attempt to defraud the victim&#8217;s customers, also known as a business email compromise (BEC) scam, was thwarted, ESET said, as business partners usually noticed something off about the hackers&#8217; follow-up emails.<\/p>\n<p>In the grand scheme of things, this isn&#8217;t surprising as North Korean hackers have repeatedly engaged in cyber-heists for the past three years, targeting both banks and cryptocurrency exchanges.<\/p>\n<p>In September 2019, the US Department of the Treasury imposed sanctions on entities associated with North Korea&#8217;s hacking units, claiming the country was <a href=\"https:\/\/www.zdnet.com\/article\/us-treasury-sanctions-three-north-korean-hacking-groups\/\" target=\"_blank\" rel=\"noopener noreferrer\">using its hacker groups to steal money and raise funds<\/a> for Pyongyang&#8217;s weapons and missile programs.<\/p>\n<p>In addition, the use of LinkedIn for approaching targets has been an old tactic employed by North Korean hackers. In January 2019, the same Lazarus hackers used LinkedIn messages to contact employees working in the banking sector and <a href=\"https:\/\/www.zdnet.com\/article\/north-korean-hackers-infiltrate-chiles-atm-network-after-skype-job-interview\/\" target=\"_blank\" rel=\"noopener noreferrer\">arrange job interviews via Skype<\/a>, where victims were given malware-laced files. This is how security researchers believe North Korean hackers breached Redbanc, the company that interconnects the ATM infrastructure of all Chilean banks.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31304\/North-Koreas-State-Hackers-Caught-Engaging-In-BEC-Scams.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":35581,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8724],"class_list":["post-35580","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinegovernmentmalwarecyberwarkoreaconference"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>North Korea&#039;s State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"North Korea&#039;s State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-17T16:02:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"540\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"North Korea&#8217;s State Hackers Caught Engaging In BEC Scams\",\"datePublished\":\"2020-06-17T16:02:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/\"},\"wordCount\":640,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg\",\"keywords\":[\"headline,government,malware,cyberwar,korea,conference\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/\",\"name\":\"North Korea's State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg\",\"datePublished\":\"2020-06-17T16:02:51+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg\",\"width\":960,\"height\":540},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/north-koreas-state-hackers-caught-engaging-in-bec-scams\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,government,malware,cyberwar,korea,conference\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinegovernmentmalwarecyberwarkoreaconference\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"North Korea&#8217;s State Hackers Caught Engaging In BEC Scams\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"North Korea's State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/","og_locale":"en_US","og_type":"article","og_title":"North Korea's State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-06-17T16:02:51+00:00","og_image":[{"width":960,"height":540,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"North Korea&#8217;s State Hackers Caught Engaging In BEC Scams","datePublished":"2020-06-17T16:02:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/"},"wordCount":640,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg","keywords":["headline,government,malware,cyberwar,korea,conference"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/","url":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/","name":"North Korea's State Hackers Caught Engaging In BEC Scams 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg","datePublished":"2020-06-17T16:02:51+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/north-koreas-state-hackers-caught-engaging-in-bec-scams.jpg","width":960,"height":540},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/north-koreas-state-hackers-caught-engaging-in-bec-scams\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,government,malware,cyberwar,korea,conference","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinegovernmentmalwarecyberwarkoreaconference\/"},{"@type":"ListItem","position":3,"name":"North Korea&#8217;s State Hackers Caught Engaging In BEC Scams"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=35580"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35580\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/35581"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=35580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=35580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=35580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}