Hacking group that hit South Korea may be at it again with new target

It appears the same malware was recently used against an organization based in Europe

A hacking group that crippled South Korean banks, government websites and news agencies in early 2013 may be active again, Palo Alto Networks said Wednesday.

The firewall maker said it found strong similarities between malware used in a recent attack in Europe and that used in the South Korean attacks, referred to as Dark Seoul and Operation Troy.

The organization in Europe that was attacked was likely a victim of spear-phishing, where an email with a malware attachment or a harmful link is sent to hand-picked employees.

The malware had been wrapped into legitimate video player software that was hosted by an industrial control systems company, wrote Bryan Lee and Josh Grunzweig of Palo Alto in a blog post. The code appears to be the same as the malware used in the Dark Seoul attacks although without the destructive component that wipes hard drives.

"It is likely the same adversary group is involved, although there is currently insufficient data to confirm this conclusion," they wrote.

The Dark Seoul attacks on March 20, 2013 wiped data from bank computers, shut down ATMs and also took down government websites.

The malware was configured to wipe a computer's Master Boot Record (MBR), the first sector of a PC’s hard drive that the computer looks to before loading the operating system.

The same kind of wiper malware also wrecked thousands of computers at Sony Pictures Entertainment last year after gigabytes of data was stolen from its network. The U.S. government blamed the attack on North Korea.

In July 2013, security vendor McAfee published an analysis of Dark Seoul attacks, which it called Operation Troy. The report also described a much less noisy parallel operation that appeared to be aimed at stealing classified military data.

It initially appeared that two separate groups -- the Whois Hacking Team and the NewRomanic Cyber Army Team -- were behind the attacks. But McAfee concluded it was likely just one group, based on an analysis the attack code.

Palo Alto said the command-and-control servers for the most recent attack are compromised websites in South Korea and Europe that appear to be running out-of-date software.

It is challenging to develop new hacking tools and malware, and it's unlikely that the group behind Dark Seoul would have shared it with other actors, Palo Alto said.

"The similarities in tactics however, do seem to outweigh the differences, and it is highly likely this is the same group or groups responsible for the original Dark Seoul/Operation Troy attacks, but with a new target and a new campaign," Palo Alto wrote.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?