#Castov

Malware/Tool

2013-05-28 • South Korean Financial Companies Targeted by Castov

Castov is malware used against South Korean financial companies and customers and also described as a DarkSeoul downloader. It was delivered through the Gongda exploit kit, while a 2013 government DDoS incident began with a trojanized file from a compromised server. An initial Delphi-compiled stage could stop antivirus software, report infection to command-and-control infrastructure, and download an encrypted second stage. Other chains unpacked payloads hidden in JPG files and used Tor to retrieve a final DDoS payload. An information-stealing component captured banking data and collected NPKI digital certificates.

Tagged Reports

« Back