New Romanic Cyber Army Team
2013-07-08 • Mcafee • Dissecting operation Troy: Cyberespionage in Sout…
McAfee's 2013 report Dissecting Operation Troy identified NewRomanic Cyber Army Team as one of two personas, alongside the Whois (Hacking) Team, that publicly claimed responsibility for the March 20, 2013 Dark Seoul attacks, which wiped the master boot records of tens of thousands of computers at South Korean banks and broadcasters and disrupted ATM access. A pop-up message left on a defaced news site and signed by NewRomanic Cyber Army Team, referencing military-unit terms embedded in the wiper malware itself, claimed theft of tens of millions of customer records. McAfee assessed that the two claiming groups were most likely fabricated personas covering for a single actor behind a covert, South Korea-focused military-espionage campaign it tracked as Operation Troy, which had used spear-phishing-delivered backdoors and an encrypted command-and-control channel to search for files referencing US-Korean military cooperation since at least 2009. Later reporting by HP and Krebs on Security linked the same wiper code and Roman-themed strings to the 2014 Sony Pictures Entertainment attack, and to threat actors alternatively tracked by other researchers as Hastati or Silent Chollima.
-
60
Related Actors
-
3
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster