Feeds

NORKS fingered for APT on South Korean think tanks

Kaspersky says 'Kimsuky' malware driven by Pyonyang

Security for virtualized datacentres

Security researchers have unearthed yet another highly targeted advanced persistent threat (APT) attack, this time launched by suspected North Korean attackers against a small group of South Korean think tanks.

The Kimsuky campaign, which can be traced back to April this year, was analysed by researchers at Kaspersy Lab in a lengthy blog post on its Securelist portal.

Although pegged as an “unsophisticated” spy program communicating with its operator through a Bulgarian public email server, it attracted their attention because some of its code contained Korean script, Kaspersky Lab’s Dmitry Tarakanov wrote.

Nevertheless, the malware was described as relatively basic, containing coding errors and even traces of infection by the Viking virus.

Tarakanov said his team isn’t sure how the attacks spread but that the samples collected are consistent with the “early stage malware” usually delivered by spear phishing emails.

An initial Trojan dropper loaded more malware onto an infected machine, disabling the system firewall and any Ahn Lab firewall installed - Ahn Lab being a popular Korean security software company.

It also turned off Windows Security Center to prevent any alerts about the disabled firewall, Tarakanov said.

The package contained several modules, each performing a single function: keylogging, directory list collection, remote control access, remote control download/execution and .HWP file theft. The latter is a file format which supports Hangul script and is used in a popular South Korean word processor.

The campaign also used a modified version of the Team Viewer remote access app rather than a bespoke backdoor to nab any interesting looking files from the victim’s machine.

Kaspersky Lab suspects North Koreans behind the attack campaign for several reasons, not least because the emails registered for “drop box mail accounts” are assigned the Korean sounding names "kimsukyang" and “Kim asdfa”.

The targets are also telling, including the Korean Ministry for Unification, the Korean Institute for Defence Analysis, and non-profit the Sejong Institute.

Tarakanov added the following:

Taking into account the profiles of the targeted organisations – South Korean universities that conduct research on international affairs, produce defence policies for government, [a] national shipping company, supporting groups for Korean unification – one might easily suspect that the attackers might be from North Korea.

The targets almost perfectly fall into their sphere of interest. On the other hand, it is not that hard to enter arbitrary registration information and misdirect investigators to an obvious North Korean origin

In terms of originating IP address, ten of them used by Kimsuky operators were located in Jilin and Liaoning province, just over the North Korean border in China

“No other IP-addresses have been uncovered that would point to the attackers’ activity and belong to other IP-ranges,” Tarakanov added. “Interestingly, the ISPs providing internet access in these provinces are also believed to maintain lines into North Korea.”

If it is a North Korean APT campaign, it won’t be the first online attack launched by Pyongyang.

In March around 30,000 PCs in banks, insurance companies and TV stations were knocked out in the “Dark Seoul” attack which the South has blamed on Norks.

Seoul has even claimed that its feisty neighbour to the north has amassed a 3000-strong cyber army of highly trained hackers ready to steal military secrets and disrupt systems. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.