북 2개 대기업 그룹 전산망 사이버테러 공격

2016-06-13 KRNPA Cyberattack against the networks of two major South Korean conglomerates by North Korea

https://police.go.kr/portal/bbs/view.do?nttId=18515&bbsId=B0000011&menuNo=200067

Thumbnail for 북 2개 대기업 그룹 전산망 사이버테러 공격

South Korea's National Police Agency attributed a long-running intrusion into two major conglomerates to North Korea, finding that attackers had abused an unauthenticated bypass flaw in an enterprise PC management product used across many organizations. Investigators said the activity began in July 2014, gave the attackers control of corporate networks, and led to the theft of 42,608 documents, including defense-industry and communications-infrastructure material. Police recovered 33 North Korean malware variants, identified 16 attack servers, and tied activity to the same Pyongyang IP address used in the 2013 DarkSeoul attacks. The case showed North Korean operators preparing disruptive cyberattacks while also collecting industrial and military-sensitive data from major South Korean enterprises.

Related Reports

« Back