lazarusholic

Everyday is lazarus.dayβ

DarkSeoul: SophosLabs identifies malware used in South Korean internet attack

2013-03-20, Sophos
https://nakedsecurity.sophos.com/2013/03/20/south-korea-cyber-attack/
#DarkSeoul

Contents

SophosLabs has identified the malware used in the major internet attack that hit systems in South Korea earlier today.
Computer networks belonging to South Korean TV broadcasters and at least two major banks in the country have been disrupted by what some have suggested was a malicious internet attack originating in North Korea.
At approximately 2pm local time, computers at the Shinhan and NongHyup banks were brought down – impacting internet banking and ATMs. Similarly, systems at the KBS, MBC, and YTN television stations were reportedly crippled – although broadcasts were not interrupted.
Some media reports have said that computers failed to boot up properly, and displayed an image of three skulls alongside a message claiming that the systems had been “hacked by Whois Team”.
However, in Sophos’s testing so far we have not been able to replicate this payload.
According to a Reuters report, LG U+, the company which provides internet services to at …