보안인증프로그램 취약점 악용 해킹 사건, 북(北) ‘라자루스’ 소행으로 확인

2023-04-19 KRNPA Hacking incident exploiting vulnerabilities in security authentication program confirmed to be the work of North Korea's ‘Lazarus'

https://www.police.go.kr/component/file/ND_fileDownload.do?q_fileSn=155789&q_fileId=d227dca2-08ed-4e3c-a956-31782b2b9954

Attachments

230419ECA1B0EAB084EC9AA9_EBB3B4EC9588EC9DB8ECA69DED9484EBA19CEAB7B_E3ebGg4.pdf (329 KB)

South Korean police attributed a hacking case exploiting financial security-authentication software vulnerabilities to Lazarus, a North Korean Reconnaissance General Bureau-linked group. Investigators said North Korea compromised a well-known domestic financial security-authentication vendor in April 2021, identified software vulnerabilities, and prepared web servers and command-and-control infrastructure over a long period. The campaign also used media-company websites as watering-hole malware distribution points, creating risk of large-scale public impact and prompting urgent software updates and defensive measures.

Related Reports

« Back