Whois Team is a name that emerged in March 2013 when attackers claimed responsibility for destructive "Dark Seoul" attacks against South Korean banks and broadcasters, defacing at least one victim website and deploying disk-wiping malware; contemporaneous reporting was initially unable to determine whether a nation-state was responsible. Later analysis connected Whois Team to a second group calling itself the NewRomanic Cyber Army Team, which claimed the 2013 attacks and left messages and imagery closely resembling those later used in the November 2014 Sony Pictures intrusion, contributing to the public case for North Korean responsibility for that attack as part of an espionage campaign researchers traced back to 2009. Separate research cautioned that the Whois Team name and its listed handles could represent a false flag, noting that a South Korean white-hat capture-the-flag team also uses the "WhoIs" moniker, and that no additional attacks under the Whois Team name were subsequently observed.
3.20 Cyber Terror
#DarkSeoul • 2013-03
The “Whois Team” attacks against South Korean targets in March 2013 involved coordinated cyberattacks on banks and broadcasting companies, where systems were disrupted and in some cases rendered unusable, accompanied by website defacements and propaganda messages left by the attackers; the operation leveraged wiper-type malware designed to destroy data and disable machines, causing large-scale service outages (e.g., banking systems and media networks going offline simultaneously), and although the attacks appeared highly visible and targeted critical infrastructure—leading to classification as cyber-terrorism—analysis suggested the tools were relatively unsophisticated and attribution remained unclear, with uncertainty over whether it was a nation-state operation or hacktivist activity, highlighting an early example of destructive malware campaigns aimed at maximizing disruption rather than stealth or data theft.
-
26
Related Reports
-
1
Affected Countries
-
161
Months Since