• 3,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

News » Russia, China, North Korea, Iran recruiting cybercriminals: Microsoft report

Russia, China, North Korea, Iran recruiting cybercriminals: Microsoft report

russia-china-north-korea-iran-cybercriminals
Photo from iStock

WASHINGTON, UNITED STATES — Russia, China, North Korea, and Iran are intensifying their recruitment of cybercriminals to steal money, gather intelligence, and influence elections. 

This trend, highlighted in Microsoft’s recent threat report, revealed that these hackers are not just stealing data. 

“They are launching ransomware, prepositioning backdoors for future destruction, sabotaging operations, and conducting influence campaigns,” said Tom Burt, Microsoft’s Corporate Vice President of Customer Security.

Government and cybercriminal convergence

The report highlights a growing collaboration between nation-states and cybercriminals. Countries such as Russia, China, North Korea, and Iran are increasingly using financially motivated hackers as “force multipliers” to bolster their cyber capabilities.

  • Russia: Russian threat actors are heavily involved in cyber operations that include espionage and influence campaigns. They use cybercriminal tools and tactics to support state objectives, often targeting sectors such as government, IT, and think tanks.
  • China: Chinese cyber activities focus on intelligence collection, particularly in the Asia-Pacific region. Chinese threat actors target military and IT entities around the South China Sea, employing sophisticated techniques to gather intelligence.
  • North Korea: Known for its financially motivated cyber operations, North Korea has been involved in significant cryptocurrency thefts. The country uses cybercrime to fund state initiatives, including its missile programs.
  • Iran: Iranian cyber activities have increasingly focused on financial gain alongside traditional espionage. Iranian actors have targeted sectors like education and government for intelligence collection and have been involved in influence operations against geopolitical adversaries.

Microsoft noted a trend where nation-states collaborate with or imitate cybercriminals to meet their goals. This convergence allows states to exploit cybercriminal expertise while maintaining plausible deniability. 

For example, North Korean hackers have reportedly stolen over $3 billion in cryptocurrency since 2017, blurring the lines between state-sponsored actions and pure cybercrime.

AI’s role in cybersecurity challenges

The use of generative artificial intelligence tools has further complicated the cybersecurity landscape, enabling more effective influence operations and attacks. 

This evolving threat demands stronger international cooperation and enhanced cybersecurity measures to protect critical infrastructure and uphold democratic processes.

Sri Lanka’s major cybercrime bust

Despite these rising threats, Sri Lankan authorities arrested over 230 Chinese nationals involved in cybercrime operations targeting international banks. The raids resulted in the seizure of 250 computers and 500 mobile phones used in the scams. 

Sri Lanka’s Foreign Minister Vijitha Herath stated that the suspects primarily targeted foreign banks and financial institutions.

China’s embassy in Colombo confirmed the arrests and mentioned that a working group was dispatched to collaborate with Sri Lankan police. 

The embassy suggested that China’s domestic crackdown on cybercriminals might have driven some to seek opportunities abroad. It further emphasized China’s commitment to strengthening law enforcement cooperation with Sri Lanka.

Read more here.

Start your
journey today

  • Independent
  • Free
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO)

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between Philippines outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4000+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
3,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 3,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 3,000 firms
  • Simple
  • Transparent
Banner Image