SICHERHEIT & DATENSCHUTZ

South Korean authorities uncover cyber attack

South Korean authorities uncover cyber attack

A state-sponsored cyber campaign in South Korea uses compromised websites to install backdoors.

In South Korea, authorities, together with four security firms, have uncovered a comprehensive cyberattack campaign conducted by state-sponsored actors. The attackers compromised trusted national websites to specifically infect visitors. They exploited a vulnerability in the locally installed financial security software AnySign4PC to install malicious software.

Security research revealed that the attackers manipulated the websites so that they could install malware on visitors' systems without any user prompt. The two main variants of the deployed backdoors are known as SIGNBT and COPPERHEDGE. This malware allows the attackers to gain unauthorized access to the affected systems and steal sensitive data.

The security firms involved in the investigation confirmed that the attackers specifically targeted users who had a vulnerable version of AnySign4PC installed. This software is commonly used in the financial sector, making the attacks particularly concerning. The fact that the attackers use trusted websites as an attack vector significantly increases the risk for users.

Details of the Campaign and Affected Websites

The campaign has been classified as highly organized and targeted. Security authorities have identified several websites that served as starting points for the attacks. These sites were altered to automatically distribute the malicious software to visitors without requiring any interaction from them. This poses a significant threat to cybersecurity, as many users trust these websites.

The security firms also found that the attackers employed various techniques to evade detection of their activities. These include the use of encryption and hiding the malicious payloads within legitimate data streams. These methods make it difficult for security solutions to detect and stop the attacks in a timely manner.

Reactions and Measures by Authorities

The South Korean authorities have promptly taken measures to secure the affected websites and stop the spread of the malware. Users are strongly urged to update their systems to the latest version of AnySign4PC to protect against the known vulnerabilities. Additionally, it is recommended to use security software to detect potential threats early.

The authorities have also issued a public warning to inform users about the risks and current threats. The security firms are working closely with the authorities to identify the attackers and initiate legal action. Investigations are still ongoing, and further details about the background of the attacks are expected to emerge.

The discovery of this cyber campaign has raised concerns in South Korea, particularly in the financial sector, which heavily relies on digital security solutions. The incidents highlight the ongoing threat posed by state-sponsored cyberattacks and the need to continuously improve cybersecurity measures.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen