DarkSeoul: SophosLabs identifies malware used in South Korean internet attack
2013-03-20 • Sophos •
https://nakedsecurity.sophos.com/2013/03/20/south-korea-cyber-attack/
SophosLabs identified the malware used in the March 2013 disruption of South Korean banks and broadcasters, where Shinhan, NongHyup, KBS, MBC, and YTN systems were reportedly affected. The malware, detected as Mal/EncPk-ACE and dubbed DarkSeoul, attempted to disable South Korean antivirus products from AhnLab and Hauri, supporting that the activity was targeted at local systems. Sophos noted the code was not especially sophisticated, with unobfuscated commands and detection already available for nearly a year. Although some media reports suggested a North Korea origin, Sophos said no strong evidence had emerged tying the Whois Team or the attack operators to North Korea.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | db4bbdc36a78a8807ad9b15a562515c4 | 2013-03-20 | 2013-07-08 |
| HASH | 5fcd6e1dace6b0599429d913850f0364 | 2013-03-20 | 2013-07-08 |
| HASH | 0a8032cd6b4a710b1771a080fa09fb87 | 2013-03-20 | 2013-04-02 |