North Korean Cyber-Attacks and Collateral Damage

2018-02-15 • Alienvault •

https://www.alienvault.com/blogs/security-essentials/north-korean-cyber-attacks-and-collateral-damage

WannaCry is presented as a highly destructive ransomware outbreak with strong evidence linking it to Lazarus, reportedly operating from North Korea, and the source uses it to examine wider collateral damage from worm-like malware connected to DPRK cyber activity. AlienVault details Rivts, a USB and hard-drive file-infecting worm first publicly seen from the Voice of Korea site, whose infection logic references DPRK Korea Computer Center software such as Nnr60.exe and Hana80.exe. The report assesses several explanations for Rivts and says the most likely is that it was developed inside the DPRK, while noting it may have been a prototype or learning project without an identified backdoor component. It also contrasts Rivts with Faedevour, a worm served through a compromised KCNA site and later found on IBM and Lenovo installation USB media, showing how worms can keep spreading long after their original operation or accidental release.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2018-02-15 2020-02-26
EMAIL [email protected] 2018-02-15 2020-02-26
HASH 7b2f8c43b4c92fb2add9fce264e9266… 2018-02-15 2020-02-25
YARA rivts_pdb 2018-02-15 2018-02-15
HASH f061cd537a657b7b375d5a56e285d58… 2018-02-15 2018-02-15
HASH 2c4c9ec8e9291ba5c73f641af2e0c3e… 2018-02-15 2018-02-15
HASH 41a712fd2111c5ddec6fe58a29c80f1… 2018-02-15 2018-02-15
HASH 2fc8751d4a5798d1ec406a8b0d5a28a… 2018-02-15 2018-02-15
HASH 4dd80d4a75d19ed59e84b93bea682be… 2018-02-15 2018-02-15
EMAIL [email protected] 2018-02-15 2018-02-15
URL http://www.vok.rep.kp/CBC/CBC_d… 2018-02-15 2018-02-15
DOMAIN a-gwas-01.slyip.net 2018-02-15 2018-02-15
DOMAIN a-gwas-01.dyndns.org 2018-02-15 2018-02-15
HASH 9c3e13e93f68970f2844fb8f1f87506… 2015-10-26 2018-02-15

Related Actors

Related Reports

« Back