DarkSeoul: SophosLabs identifies malware used in South Korean internet attack

2013-03-20 Sophos

https://nakedsecurity.sophos.com/2013/03/20/south-korea-cyber-attack/

SophosLabs identified the malware used in the March 2013 disruption of South Korean banks and broadcasters, where Shinhan, NongHyup, KBS, MBC, and YTN systems were reportedly affected. The malware, detected as Mal/EncPk-ACE and dubbed DarkSeoul, attempted to disable South Korean antivirus products from AhnLab and Hauri, supporting that the activity was targeted at local systems. Sophos noted the code was not especially sophisticated, with unobfuscated commands and detection already available for nearly a year. Although some media reports suggested a North Korea origin, Sophos said no strong evidence had emerged tying the Whois Team or the attack operators to North Korea.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db4bbdc36a78a8807ad9b15a562515c4 2013-03-20 2013-07-08
HASH 5fcd6e1dace6b0599429d913850f0364 2013-03-20 2013-07-08
HASH 0a8032cd6b4a710b1771a080fa09fb87 2013-03-20 2013-04-02

Related Reports

« Back