« 2015 »

11 reports

2015-12-30 • CSIS

CSIS examines North Korea's cyber operations after the 2013 attacks on South Korean banks and media agencies and the 2014 Sony Pictures Entertainment breach. The excerpt frames DPRK cyber activity as a strategic issue, asking why North Korea pursues cyber…

#Trend
2015-11-20 • GIAC

GIAC’s DarkSeoul case study describes destructive malware that crippled tens of thousands of South Korean banking and media-sector systems, wiping Windows and Unix-like hosts and disrupting ATMs, payment terminals, and mobile banking. The paper says South…

#DarkSeoul
2015-09-09 • Fireeye

FireEye analyzed malicious Hangul Word Processor documents exploiting CVE-2015-6585, a then unknown HWPX parsing vulnerability in hwpapp.dll. The exploit abuses a type confusion condition in para text handling, uses Unicode values and heap spraying to red…

#CVE-2015-6585
2015-09-01 • Somansa

Somansa analyzes malicious HWP documents attributed in the report to Kimsuky and aimed at specific South Korean institutions through a Hangul Office vulnerability that had already been patched. The documents use heap spraying and shellcode to extract encr…

#Kimsuky