N. Korea uses upgraded backdoor scheme to attack U.S. video-conferencing firm 3CX

North Korea has used its upgraded skills to stage a backdoor attack against the network of U.S. virtual phone service company 3CX last month, Mandiant, Google’s cybersecurity unit, said Thursday.

3CX, which provides online voice, video conferencing and messaging services for businesses, saw its network chain had been attacked by information-stealing malware planted by a hacker cluster named UNC4736. It is known to be a Lazarus sub-group dubbed Labyrinth Chollima, while Lazarus is one of the North Korean government-led secret operations organizations.

“We believe a North Korean nexus threat actor, who we are calling UNC4736, was behind this attack,” Charles Carmakal, consulting chief technology officer at Mandiant, said at an online media briefing.

He said Mandiant, which has worked with 3CX to look into the massive breach, discovered that the hackers have not directly attacked the company’s network. Instead, they had planted the malware into a separate software package of X Trader, a U.S. financial trading application, and led to the malicious code being transferred to the 3CX network through a 3CX employee’s personal computer.

“What happened was an employee of 3CX installed the X Trader software on his personal computer, and it ended up deploying a backdoor on his personal computer, because the X Trader software was laced with malware that we call a veiled signal.”

The Mandiant official said the method employed in the attack was higher and more sophisticated than the previous schemes that North Korea had used in committing cybercrimes.

“This is very notable to Mandiant because this is the first time that we’ve ever observed a software supply chain attack lead to another software supply chain attack,” he said. “A North Korean threat actor really stepped up their skill and their sophistication, such that they’re able to conduct a cascading software supply chain attack.”

The company also said North Korea’s latest attack against 3CX is targeting cryptocurrency, widely believed to be a source of funding for the reclusive country’s nuclear program.

“I think this is likely financially motivated as sort of an end goal, but this targeting also appears to be somewhat opportunistic in terms of the software supply chain,” said Ben Read, head of cyber espionage analysis at Mandiant. “This backdoor would allow the North Korean actors in this case to gather some rudimentary information about the server and, sort of more importantly, pull down additional malware to enable more functionality and spread throughout the network.”

Source: Yonhap News Agency

S. Korea beats Slovenia for 3rd straight win at women’s hockey worlds

South Korea rallied past Slovenia 4-2 at the third-tier women’s hockey world championship on home ice Thursday, registering its third straight victory to position itself for a promotion to the next level in international hockey.

Lee Eun-ji scored twice, and Park Jong-ah had a goal and two helpers, as South Korea stayed at the top of the standings at the International Ice Hockey Federation (IIHF) Women’s World Championship Division I Group B at Suwon Ice Rink in Suwon, some 35 kilometers south of Seoul.

This six-nation tournament is the third-highest level of the IIHF women’s world championships, below the World Championship and World Championship Division I Group A.

The winner of this tournament after round-robin play will be promoted to the Division I Group A for next year. South Korea has never made it past the Division I Group B.

South Korea leads the way with eight points after two wins in regulation and one win in overtime, followed by Italy at seven points. South Korea is the only undefeated team in the tournament so far.

Earlier Thursday, Italy shut out Kazakhstan 3-0, and Poland beat Britain 2-1.

For the first time in the tournament, South Korea gave up the first goal of a game Thursday. At 5:41 mark in the first period, Pia Pren beat goalie Huh Eun-bee to the top shelf, after South Korea failed to clear the loose puck out of the defensive zone.

But South Korea tied things up less than three minutes later. On a power play, Han Soo-jin and Park Jong-ah played a deft give-and-go, with Park setting up Han with a diagonal pass from behind the net to fool goalie Pia Dukaric.

Lee Eun-ji put South Korea up 2-1 at 7:29 in the second period, redirecting home a point shot by defender Kim Se-lin.

Park Jong-ah’s goal off a rebound from a Lee So-jung point shot made it 3-1 for South Korea at 4:12 mark in the third period.

Some three minutes later, Lee Eun-ji scored her second goal of the game on a power play, with a one-timer off a pass by Park from below the goal line.

Slovenia scored a power play goal at 9:15, as Sara Confidenti’s shot went in off a skate to catch Huh off guard in the Korean net. But the Europeans couldn’t get any closer, as South Korea kept peppering the Slovenian net with shot after shot.

South Korea outshot Slovenia 44-14.

South Korea will next face Britain at 3:45 p.m. Saturday and then finish the competition against Kazakhstan at 3:45 p.m. Sunday.

Source: Yonhap News Agency

TRAFFIC SLOW MOVING ON MAJOR HIGHWAYS THIS EVENING

Traffic flow at several major highways nationwide is reported to be slow moving as of 6 pm following an influx of people returning to their hometowns to celebrate Hari Raya Aidilfitri.

The Malaysian Highway Authority (LLM) said that, based on the current trend, traffic congestion is set to get worse from tonight, especially after the breaking of fast.

“Right now, there are traffic snarls in several areas, especially due to accidents. Among them is the 14-kilometre (km) congestion on the North-South Expressway (PLUS) heading south from Southville City to Seremban and Putra Mahkota to Nilai.

“Traffic on PLUS from the north is also slow moving, from Slim River to Sungkai, Sungkai to the lay-by at Ladang Bikam, Bidor to Tapah, Ipoh Utara to Kuala Kangsar and Juru to Bertam,” it said when contacted by Bernama.

In addition, traffic congestion is detected at several hotspots on the Kuala Lumpur-Karak Expressway, namely after the Gombak Toll Plaza to Lentang and Genting Sampah as well as after the tunnel to Bukit Tinggi.

“Traffic at Pantai Timur Highway (LPT) 1 is smooth flowing for now and the LPT 2 is a bit congested before the exit at the Kuala Terengganu Toll Plaza,” it said.

Meanwhile, a PLUS spokesman said that for northbound, an accident at KM 434 from Bukit Beruntung to Sungai Buaya had resulted in the closure of the left lane for diversion purposes.

Apart from that, traffic flow is also slow southbound following an accident at KM 307 from Universiti Putra Malaysia to Kajang.

The public can stay updated on the latest traffic situation through the Plusline toll-free line at 1800-88-0000, the Twitter page at www.twitter.com/plustrafik or the LLM line at 1800-88-7752 and the Twitter page at www.twitter.com/llminfotrafik.

Source: BERNAMA News Agency

MUSLIMS IN MALAYSIA CELEBRATE AIDILFITRI ON SATURDAY

Muslims in Malaysia will celebrate Hari Raya Aidilfitri on Saturday (April 22), the Keeper of the Rulers’ Seal Tan Sri Syed Danial Syed Ahmad announced.

“In keeping with the command of the Yang di-Pertuan Agong, following the consent of the Rulers, I hereby declare that the date for Hari Raya Puasa for the states in Malaysia has been set for Saturday, April 22, 2023,” he said.

The announcement was broadcast over local television networks.

Source: BERNAMA News Agency

Australia Commends Cambodia’s Rapid Progress

Australia has praised noticeably fast progress and development of Cambodia in all domains, especially transport infrastructure sector.

The remark was made by H.E. Justin Kevin Whyatt, newly appointed Ambassador of Australia to Cambodia, while paying a courtesy call on H.E. Sun Chanthol, Senior Minister and Minister of Public Works and Transport, at the ministry office yesterday.

H.E. Justin Kevin Whyatt voiced his pleasure of returning to work in Cambodia again after more than two decades, and expressed his strong willingness during his diplomatic mission in the country to strengthen and expand bilateral cooperation between both countries effectively, as well as promote and reinforce bilateral relations between Australian private investors in Cambodia on cooperation in the fields of transport infrastructure and logistics.

The Australian ambassador also revealed his interest in Temperature Controlled Logistics (TCL) which ensures that the storage, preservation, and transportation of cargo remain within the correct temperature condition from start to finish line in order to support the economic development of Cambodia through providing employment opportunities for people to serve agro-industrial, food processing and pharmaceutical companies, food retailers, and hospitality businesses such as hotels and restaurants.

Taking the opportunity, H.E. Justin Kevin Whyatt shared his optimism, support and encouragement that the Kingdom of Cambodia is going to proudly host the upcoming 32nd SEA Games and 12th ASEAN Para Games while the country is waiting for 64 years for the auspicious celebration of the regional games, wishing Cambodia a fruitful result and a new honour in sports filed.

For his part, H.E. Sun Chanthol informed his guest about new development projects that have been implemented to improve the connection of transport infrastructure sector throughout the country like logistics master plan preparation, Phnom Penh Logistics Centre (PPLC) development project, Sihanoukville Logistics Centre development project, Tonle Bassac Navigation and Logistics System Project, Expressway projects, and upgrading project of Phnom Penh-Poipet railway to MRT, and more.

The minister also mentioned about the encouragement of the use of electric vehicles (EVs) in Cambodia through Draft Law on EVs.

Source: Agence Kampuchea Presse