Tag Archive for: Korean

South Korean web hosting company infected by Erebus ransomware

Nayana, a web hosting company in South Korea, suffered a ransomware attack over the weekend which resulted in more than a hundred Linux servers and thousands of websites being infected with Erebus ransomware. The initial ransom amount was astronomically high.

Yesterday, I came across the news that a South Korean web hosting company had been infected by ransomware, but it was extremely short on details. The ransomware was Erebus; the attack occurred on Saturday and thousands of sites were reportedly infected.

Today, Aju Business Daily provided more details. Nayana reportedly said 153 of its Linux servers were infected with Erebus. In turn, about 3,400 sites on the web hosting company’s servers were also infected.

To read this article in full or to leave a comment, please click here

Network World Security

North Korean Hackers Are Scarier Than North Korean Nukes – Yahoo Finance UK

North Korean Hackers Are Scarier Than North Korean Nukes
Yahoo Finance UK
Chinese technicians work at the Recovery Key Laboratory of Sichuan province in Chengdu, China on May 15, where anti-ransomware software was released to recover files encrypted by the international ''WannaCry'' cybersecurity attack, which may have …

and more »

China hackers – read more

Shared malware code links SWIFT-related breaches at banks and North Korean hackers

Malware links suggest that North Korean hackers might be behind recent attacks against several Asian banks, including the theft of US$ 81 million from the Bangladesh central bank earlier this year.

Security researchers from Symantec have found evidence that the malware used in the Bangladesh Bank cyberheist was used in targeted attacks against an unnamed bank in the Philippines. The same malware was also previously linked to an attempted theft of $ 1 million from Tien Phong Bank in Vietnam.

Symantec confirmed the earlier findings of researchers from BAE Systems who found code similarities between the Bangladesh Bank malware, which was used to modify SWIFT transfers, and the malicious program used in attacks against Sony Pictures Entertainment in December 2014.

To read this article in full or to leave a comment, please click here

Network World Security

North Korea is likely behind attacks exploiting a Korean word processing program

North Korea is likely behind cyberattacks that have focused on exploiting a word processing program widely used in South Korea, security firm FireEye said Thursday in a report.

The proprietary program, called Hangul Word Processor, is used primarily in the south by the government and public institutions.

The vulnerability, CVE-2015-6585, was patched three days ago by its developer Hancom.

FireEye’s conclusion is interesting because only a handful of attacks have been publicly attributed to the secretive nation, which is known to have well-developed cyber capabilities.

To read this article in full or to leave a comment, please click here

Network World Security