농협 전산망 장애사건 수사 결과

2011-05-03 KRSPO Results of investigation into Nonghyup computer network failure incident

https://www.slideserve.com/cahil/5682386

Attachments

2116602603.pdf (1 MB)

Thumbnail for 농협 전산망 장애사건 수사 결과

A Korean prosecution presentation reconstructs the 2011 NongHyup banking disruption as a prepared destructive cyberattack that progressed from website-based malware infection to keylogging, backdoor installation, command-file staging, and execution of file deletion and system-destruction commands. The timeline shows attackers collecting IP addresses, passwords, and chat contents from March to April before triggering destructive activity on April 12, causing failures across internal, web, and test servers. The incident affected 273 of 587 total servers, including 180 internal servers and 45 web servers, with recovery of branch, ATM, card, and customer services taking days to weeks. The slides compare malware and command-line construction with the 7.7 DDoS and 3.4 DDoS incidents, including high overlap in samples and shared password-key characteristics, making the case for related destructive tradecraft against South Korean financial infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 9.43.216.108 2011-05-03 2011-05-03

Related Reports

« Back