Menu
Hacking group that hit South Korea may be at it again with new target

Hacking group that hit South Korea may be at it again with new target

It appears the same malware was recently used against an organization based in Europe

A hacking group that crippled South Korean banks, government websites and news agencies in early 2013 may be active again, Palo Alto Networks said Wednesday.

The firewall maker said it found strong similarities between malware used in a recent attack in Europe and that used in the South Korean attacks, referred to as Dark Seoul and Operation Troy.

The organization in Europe that was attacked was likely a victim of spear-phishing, where an email with a malware attachment or a harmful link is sent to hand-picked employees.

The malware had been wrapped into legitimate video player software that was hosted by an industrial control systems company, wrote Bryan Lee and Josh Grunzweig of Palo Alto in a blog post. The code appears to be the same as the malware used in the Dark Seoul attacks although without the destructive component that wipes hard drives.

"It is likely the same adversary group is involved, although there is currently insufficient data to confirm this conclusion," they wrote.

The Dark Seoul attacks on March 20, 2013 wiped data from bank computers, shut down ATMs and also took down government websites.

The malware was configured to wipe a computer's Master Boot Record (MBR), the first sector of a PC’s hard drive that the computer looks to before loading the operating system.

The same kind of wiper malware also wrecked thousands of computers at Sony Pictures Entertainment last year after gigabytes of data was stolen from its network. The U.S. government blamed the attack on North Korea.

In July 2013, security vendor McAfee published an analysis of Dark Seoul attacks, which it called Operation Troy. The report also described a much less noisy parallel operation that appeared to be aimed at stealing classified military data.

It initially appeared that two separate groups -- the Whois Hacking Team and the NewRomanic Cyber Army Team -- were behind the attacks. But McAfee concluded it was likely just one group, based on an analysis the attack code.

Palo Alto said the command-and-control servers for the most recent attack are compromised websites in South Korea and Europe that appear to be running out-of-date software.

It is challenging to develop new hacking tools and malware, and it's unlikely that the group behind Dark Seoul would have shared it with other actors, Palo Alto said.

"The similarities in tactics however, do seem to outweigh the differences, and it is highly likely this is the same group or groups responsible for the original Dark Seoul/Operation Troy attacks, but with a new target and a new campaign," Palo Alto wrote.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

How MSPs can capitalise on integrating AI into existing services

How MSPs can capitalise on integrating AI into existing services

​Given the pace of change, scale of digitalisation and evolution of generative AI, partners must get ahead of the trends to capture the best use of innovative AI solutions to develop new service opportunities. For MSPs, integrating AI capabilities into existing service portfolios can unlock enhancements in key areas including managed hosting, cloud computing and data centre management. This exclusive Reseller News roundtable in association with rhipe, a Crayon company and VMware, focused on how partners can integrate generative AI solutions into existing service offerings and unlocking new revenue streams.

How MSPs can capitalise on integrating AI into existing services
Access4 holds inaugural A/NZ Annual Conference

Access4 holds inaugural A/NZ Annual Conference

​Access4 held its inaugural Annual Conference in Port Douglass, Queensland, for Australia and New Zealand from 9-11 October, hosting partners from across the region with presentations on Access4 product updates, its 2023 Partner of the Year awards and more.

Access4 holds inaugural A/NZ Annual Conference
Show Comments