« 2013 »

31 reports

2013-05-28 • Symantec

Symantec observed the Gongda exploit kit, which was mainly targeting South Korea, delivering Castov malware against specific South Korean financial companies and their customers. The initial Delphi-compiled stage can stop antivirus software, report the in…

#Castov
2013-04-24 • Malware-reversing

The excerpt is a sample catalog rather than a full malware analysis, grouping related tools by PDB/debug strings: Concealment Troy, Http Dr0pper, Http Troy, PDF Exploit, TDrop, and additional package parts. It records PE timestamps from 2011-2013, MD5 has…

#DarkSeoul
2013-04-10 • Issuemakers Lab

IssueMakersLab attributed the March 20 attacks on South Korean broadcasters and banks to a hacker group it said had conducted a long-running campaign against South Korea since 2007. The report connected the March 2013 activity to earlier operations throug…

#1Mission
2013-04-10 • KRCERT

A South Korean joint civilian-government-military investigation linked the March 2013 broadcast and financial-sector destructive attacks to methods previously associated with North Korean operations, while describing the attribution as based on accumulate…

#DarkSeoul
2013-04-02 • Zataz

The March 2013 Dark South Korea attack disrupted South Korean banks and broadcasters including KBS, MBC, YTN, Nonghyup, Shinhan, and Cheju, with roughly 47,800 systems reported impacted. The excerpt separates the activity into wiper, drop-and-wipe, drop-a…

#DarkSeoul
2013-03-23 • NSHC

DarkSeoul is described as a cyber threat report requiring defender review of the published evidence. The source discusses attacker tradecraft, victim targeting, malware or infrastructure references, and operational context that may affect detection engine…

#DarkSeoul
2013-03-22 • Stolen Byte

WOWHACKER Group analyzed malware used in the March 20, 2013 South Korea cyberattack. The binary dynamically loads Windows libraries and APIs, checks for a file mapping marker to avoid repeat execution, kills security related processes such as pasvc.exe an…

#DarkSeoul
2013-03-21 • Secure Works

Dell SecureWorks analyzed destructive Wiper malware used in the March 20, 2013 attacks that disrupted South Korean broadcasters, banks, and other financial-sector systems. The dropper extracted Windows wiper components, PuTTY SSH/SCP binaries, and a Unix …

#DarkSeoul #Wiper #Hastati