New Romanic Cyber Army Team

2013-07-08 • McafeeDissecting operation Troy: Cyberespionage in Sout…

McAfee's 2013 report Dissecting Operation Troy identified NewRomanic Cyber Army Team as one of two personas, alongside the Whois (Hacking) Team, that publicly claimed responsibility for the March 20, 2013 Dark Seoul attacks, which wiped the master boot records of tens of thousands of computers at South Korean banks and broadcasters and disrupted ATM access. A pop-up message left on a defaced news site and signed by NewRomanic Cyber Army Team, referencing military-unit terms embedded in the wiper malware itself, claimed theft of tens of millions of customer records. McAfee assessed that the two claiming groups were most likely fabricated personas covering for a single actor behind a covert, South Korea-focused military-espionage campaign it tracked as Operation Troy, which had used spear-phishing-delivered backdoors and an encrypted command-and-control channel to search for files referencing US-Korean military cooperation since at least 2009. Later reporting by HP and Krebs on Security linked the same wiper code and Roman-themed strings to the 2014 Sony Pictures Entertainment attack, and to threat actors alternatively tracked by other researchers as Hastati or Silent Chollima.

Related Actors

Related Reports in This Cluster

Top Authors

View New Romanic Cyber Army Team reports only

View New Romanic Cyber Army Team reports only