#Koredos

Malware/Tool

2011-03-11 • Trojan.Koredos Comes with an Unwelcomed Surprise

Trojan.Koredos is destructive malware used in coordinated distributed denial-of-service attacks against South Korean websites. Rather than receiving live instructions from a command-and-control server, its attack commands are embedded within the threat. One component destroys the master boot record after a trigger condition, while some variants scan fixed drives for Korean software file types such as ALZ, GUL, and HWP. Targeted files are overwritten with zeros or deleted, making recovery difficult, and infected computers may remain operational for up to ten days before destruction occurs.

Tagged Reports

« Back