« 2013 »

31 reports

2013-09-11 • Kaspersky

Kaspersky described a months-long cyber-espionage campaign, named the Kimsuky operation, targeting South Korean think tanks, defense policy bodies, the Ministry of Unification, Hyundai Merchant Marine, and related organizations. The malware used Korean-la…

#Kimsuky
2013-07-19 • HNS

The 6.25 DNS DDoS malware used compromised Simdisk distribution infrastructure to infect PCs and redirect DNS amplification traffic toward South Korean government DNS servers. The report, based on Fortinet's analysis, says the SimDisk_setup.exe package dr…

#6.25CyberTerror #DDoS
2013-07-09 • Ahnlab

AhnLab’s analysis of the June 25, 2013 cyberattack describes DDoS activity against South Korean government and media-related targets beginning at 10:00 local time. One attack path used malware distributed through modified webhard installer and update file…

#6.25CyberTerror
2013-06-26 • Fireeye

FireEye's 6.25 Cyber Attack Analysis Report describes the June 25, 2013 campaign in which attackers modified a web-hard installer to distribute malware, build a botnet, and trigger DDoS activity at a scheduled time. The report says the malware used Themid…

#6.25CyberTerror
2013-06-25 • Fortinet

Fortinet Korea's 6.25 DNS DDoS report attributes the June 25 disruption of South Korean government sites to malware that abused infected hosts to attack the government DNS servers ns.gcc.go.kr and ns2.gcc.go.kr. The initial sample was downloaded from simd…

#6.25CyberTerror #DDoS
2013-06-10 • Malwarelu

Malware.lu CERT and itrust analyzed a suspicious PDF named “Draft response letter Slovenia.pdf” that they identify as KimJongRAT/Stealer after it was uploaded to malwr.com in May 2013. The document describes a PDF exploit that deploys sysninit.ocx and a l…

#KimjongRAT