2013年3月に発生した韓国へのサイバー攻撃をまとめてみた
2013-03-23 • piyokango • A summary of the cyber attacks on South Korea that occurred in March 2013 •
The Japanese roundup compiles government, media, vendor, and independent reporting on the March 2013 South Korean cyberattack that disrupted financial institutions and broadcasters and affected tens of thousands of PCs and servers. It describes destructive malware being delivered through asset-management or security update infrastructure, with AhnLab later reporting an authentication-bypass weakness in its management product and IssueMakersLab attributing the intrusion path to a longer Operation 1Mission campaign. The Korean government joint response team reportedly assessed, based on circumstantial evidence, that North Korea's Reconnaissance General Bureau was likely involved, while the excerpt stresses that the claim was presented as an estimate rather than definitive proof. IssueMakersLab's account describes activity beginning around 2012, dozens of first-stage C2 servers, hacked Korean web servers used for malware distribution, staged downloads, encrypted communications, password and XTEA-key reuse, and later destructive variants. The roundup also notes related disruptions affecting Daily NK and other North Korea-focused activist sites, while distinguishing some later outages as unrelated hardware or internal system problems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | busan.com | 2013-03-23 | 2013-03-23 |
| DOMAIN | bluekoreadot.com | 2013-03-23 | 2013-03-23 |
| DOMAIN | kado.net | 2013-03-23 | 2013-03-23 |