하나투어 해킹 사건으로 대규모 사이버 공격 전모 밝혀지나

2017-11-17 Boannews Hana Tour hacking incident reveals the full story of a large-scale cyber attack

http://m.boannews.com/html/detail.html?idx=58091

Thumbnail for 하나투어 해킹 사건으로 대규모 사이버 공격 전모 밝혀지나

Boannews reports that the Hanatour personal data breach was linked to a specific vendor solution that appears to have served as an attack entry point. Malware found at Hanatour was described as a variant similar to samples seen in an SI vendor intrusion and in other environments, including asset management and banking organizations. The article says the malware communicated with an IP range tied to a shopping mall server hosted through the SI vendor's IDC, which was suspected of being abused as command-and-control infrastructure. Researchers also noted similarities to malware used against Seoul ADEX participants and major Korean conglomerate affiliates, raising the possibility that the activity was part of the suspected North Korean Operation GoldenAxe campaign, though the report frames this as a likelihood rather than definitive attribution.

Related Reports

« Back