Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

North Korea Behind Bank Malware, South Korea Says

Evidence ties North Korean cyber-espionage unit to two waves of attacks on banks and broadcasters, South Korean officials say.

The March wiper malware attack that deleted data at South Korean banks and broadcasters was launched by a North Korean cyber-espionage unit, South Korean government officials claimed Wednesday.

"An analysis of cyber-terror access logs, malicious code and North Korean intelligence showed that the attack methods were similar to those used by the North's Reconnaissance General Bureau, which has led hacking attacks against South Korea," said Lee Seung-won, an official at South Korea's Ministry of Science, ICT & Future Planning, at a Wednesday press conference, reported South Korea's news agency, Yonhap.

The highly targeted malware attacks infected systems at South Korean banks Jeju, NongHyup and Shinhan, and their insurance affiliates, as well as South Korean broadcasters KBS, MBC and YTN. The attacks occurred on March 20, although systems in some cases had been previously infected with malware that included a logic bomb set for that date. As a result of the attacks, some online and mobile banking operations, as well as ATMs, temporarily froze. The attack is now believed to have compromised a total of 48,000 PCs, revising earlier estimates of 32,000 PCs.

[ Tension is escalating between North and South Korea. See South Korea Charges Alleged Hackers. ]

According to Yonhap, South Korean officials further disclosed Wednesday that a second wave of attacks on March 25 and 26 targeted 58 servers and 14 websites -- including sites operated by North Korean defectors -- that are opposed to the North Korean regime in Pyongyang headed by 30-year old Kim Jong-un.

The South Korean government probe further found that planning for the March 2013 malware campaign began in June 2012, if not earlier. "North Korean PCs first used local infiltration routes to test the attack orders in February" of this year, said Chun Kil-soo, head of the Korea Internet Security Center at the government's Korea Internet & Security Agency. For the attacks, at least six PCs were used to distribute 76 different types of malware, 18 of which had previously been seen only in cyber attacks launched by North Korea.

Officials said South Korean networks targeted in the March attacks had been directly accessed at least 13 times from systems known to be operated by North Korea. Of the 49 "infiltration routes" government investigators identified, 25 were via networks in South Korea and 24 were from outside the country -- and 22 of those foreign IP addresses had been used since 2009 by Pyongyang to launch cyber attacks.

In the wake of the malware attacks, a Korean Communications Commission official accused North Korea of launching at least some of the attacks via an IP address in China. But South Korean government officials quickly recanted that attribution, saying they'd misread a private IP address assigned to NongHyup bank as being registered in China, and that it was too early to assign blame.

In fact, at least one system at NongHyup was used to distribute the attacks, which deleted data from Windows, Unix and Linux systems. According to South Korean antivirus vendor AhnLab's Security Emergency Response Center (ASEC), at least some of the attacks were distributed via AhnLab's enterprise patch management software at the targeted sites, which attackers accessed using legitimate -- but stolen -- usernames and passwords. ASEC's research found that "once the attackers had access to the patch management system they used it to distribute the malware much like the system distributes new software and software updates."

South Korean officials have claimed that a North Korean cyber-warfare unit -- dubbed "No. 121" -- includes roughly 3,000 personnel who have been trained in malware development and network infiltration.

The results of South Korea's wiper malware probe were detailed on the same day that South Korea's foreign minister, Yun Byung-se, warned that North Korea had placed a mid-range Musudan ballistic missile on its east coast. "According to intelligence obtained by our side and the U.S., the possibility of a missile launch by North Korea is very high," Yun told a parliamentary hearing, saying a launch of one or more missiles could happen "any time from now." The Musudan missile is believed to have a range of 3,500 kilometers, meaning it could strike not only South Korea and Japan but also Guam.

In response to the missile repositioning, American and South Korean troops Wednesday increased their alert levels, reported The New York Times. On a related note, the White House earlier this month announced that an anti-missile system scheduled to be deployed in Guam in 2015 -- called Thaad, for Terminal High Altitude Area Defense -- would instead be deployed by the end of the month.

Easily overlooked vulnerabilities could put your data and business at risk. Also in the new, all-digital 10 Web Threats special issue of Dark Reading: How hackers compromised an iOS developers' website to exploit Java plug-in vulnerabilities and attack Apple, Facebook, Microsoft and Twitter. (Free with registration.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Computer Repair Whiteplains NY
50%
50%
Computer Repair Whiteplains NY,
User Rank: Apprentice
4/11/2013 | 3:03:38 PM
re: North Korea Behind Bank Malware, South Korea Says
It is time to sharpen the Internet blades against North Korea.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13991
PUBLISHED: 2020-09-24
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
CVE-2020-15160
PUBLISHED: 2020-09-24
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
CVE-2020-15162
PUBLISHED: 2020-09-24
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
CVE-2020-15843
PUBLISHED: 2020-09-24
ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Install\ and %PROGRAMFILES%\ActiveFax\Terminal\. The folder permissions allow "Full Control" t...
CVE-2020-17365
PUBLISHED: 2020-09-24
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially craf...