October 21, 2021

New Rule From US Commerce May Help Limit Spread of North Korean Cybercrime

The U.S. Commerce Department recently announced a new rule barring the export and resale of cyber “intrusion software” and equipment to China and Russia without a proper license from the U.S. Bureau of Industry and Security (BIS). It will apply to any intrusion software, including defensive products, being sold to any Chinese or Russian person regardless of whether they are affiliated with the government or not. Set to come into effect in 90 days, the rule will likely impact the operations of not only Chinese and Russian cybercriminals, but also the North Korean Lazarus Group, which conducts offensive cyber operations against foreign states, often with the assistance of Chinese or Russian groups.

As sanctions tighten in other areas, such as the commodities trade, North Korea continues to compensate for its monetary losses with funds obtained through illicit cyber activity.

While intrusion software is critical for penetration testing, which allows cybersecurity analysts to discover and patch existing system vulnerabilities, malicious actors have leveraged the sale and distribution of such technology to proliferate global cybercrimes. North Korea, in particular, has successfully incorporated cyber-enabled financial crime within its proliferation finance modus operandi for years as it provides an inexpensive and low-risk way to evade U.S. and U.N. economic sanctions. As sanctions tighten in other areas, such as the commodities trade, North Korea continues to compensate for its monetary losses with funds obtained through illicit cyber activity. These money-generating attacks range from basic data breaching tactics such as email phishing to more advanced forms of cyber-enabled financial crime including online bank heists, hacking of cryptocurrency transactions, and distributing ransomware.

Read the full article from The Diplomat.

  • Reports
    • April 4, 2024
    Sanctions by The Numbers: The Russian Energy Sector

    Since 2014, the United States, the European Union (EU), and other like-minded nations have targeted the Russian energy sector with increasingly significant coercive economic m...

    By Jocelyn Trainer, Nicholas Lokker, Kristen Taylor & Uliana Certan

  • Commentary
    • Sharper
    • March 20, 2024
    Sharper: Regulating Technology

    The pace of technological change presents both immense opportunity for private industry and complex challenges for national security. These technologies, including artificial ...

    By Anna Pederson & Julia Arnold

  • Podcast
    • March 18, 2024
    Can Europe fund its defense ambitions?

    The majority of European members of NATO are not spending as much on defense as they agreed to. But that may change as the European Union considers a move to a "war economy." ...

    By Rachel Ziemba

  • Commentary
    • Barron's
    • March 15, 2024
    A New Approach to Sanctions Is Pushing Up Energy Prices and Crimping Russia’s Revenue

    Heightened U.S. sanctions enforcement has also raised the importance of China as the buyer of last resort for Russia....

    By Rachel Ziemba

View All Reports View All Articles & Multimedia