South Korean attacks used spear phishing

By

Malware activated after research.

Spear phishing emails were used in recent attacks against South Korean corporations researchers say.

South Korean attacks used spear phishing

Attacks hid the file extensions of the malicious HTML-based attachments with long file names, a tactic which surfaced a decade ago.

“Those with keen eyes would notice that the malware inside the archive is using double extensions combined with a very long file name to hide the real extension,” F-Secure researcher Broderick Aquilino said.

“This is a common social engineering tactic that started during the era of mass mailing worms almost a decade ago. Therefore, we believe the archive is most likely sent as [an] attachment in spear phishing emails.”

F-Secure analysed malware which appeared to reach victims on 17 March, though it was set to wipe files three days later when South Korean companies reported downed websites, blocked servers and infections that erased computer files.

According to The New York Times, NongHyup and Jeju, major banks in South Korea, reported malware outbreaks that destroyed computer files. The Times also reported that Shinhan Bank's internet banking servers were temporarily blocked on Wednesday.

The computers of employees of KBS and MBC, television stations in South Korea, reportedly froze, as well, in addition to KBS' website becoming inoperable.

Symantec found four variants of a data-wiping trojan dubbed Jokra that were used in the attacks.

Two strains of the malware were designed to immediately wipe data upon execution, while the others were set to carry out the tasks at 2 pm and 3 pm last Wednesday.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Eagers Automotive finds unauthorised access to parts of IT systems

Eagers Automotive finds unauthorised access to parts of IT systems

Hackers hit Victoria's court recording database

Hackers hit Victoria's court recording database

St Vincent's Health Australia warns cyber attack forensics could "take some time"

St Vincent's Health Australia warns cyber attack forensics could "take some time"

Yakult Australia confirms cyber incident

Yakult Australia confirms cyber incident

Log In

  |  Forgot your password?