Kaspersky highlights connect between cyber attacks on South Korean military, ATM theft

Image
ANI New Delhi [India]
Last Updated : Jul 11 2017 | 1:57 PM IST

Kaspersky Lab researchers on Monday established a connect between a 2016 cyber espionage attack on South Korea's defense agency and a subsequent attack that infected 60 ATMs and stole the data from over 2,000 credit cards.

Further, the malicious code and techniques used in both attacks share similarities with earlier attacks widely attributed to the infamous Lazarus group, responsible for series of devastating attacks against commercial and government organisations around the world.

In August 2016, a cyber attack on South Korea's Ministry of National Defense infected around 3,000 hosts. The Defense Agency reported the incident publically in December 2016, admitting that some confidential information could have been exposed.

Six months later, at least 60 ATMs in South Korea, managed by a single local vendor, were compromised with malware. The incident was reported by the Financial Security Institute and, according to the Financial Supervisory Service, resulted in the theft of the details of 2,500 financial cards and the illegal withdrawal in Taiwan of approximately USD 2,500 from these accounts.

Kaspersky Lab researched the malware used in the ATM incident and discovered that the machines were attacked with the same malicious code used to hit the Korean Ministry of National Defense in August 2016.

Exploring the connection between these attacks and earlier hacks, Kaspersky Lab found similarities with the Dark Seoul malicious operations, and others, which are attributed to the Lazarus hacking group. The commonalities include the use of the same decryption routines and obfuscation techniques, overlap in command and control infrastructure, and similarities in code.

Lazarus is an active cybercriminal group believed to be behind a number of massive and devastating cyber attacks worldwide, including the Sony Pictures hack in 2014 and the USD 81 million Bangladesh Bank heist last year.

"While neither the military nor the ATM attacks were huge and damaging, they are evidence of a worrying trend. South Korea has been the target of cyber espionage attacks since at least 2013, but this is the first time that its ATMs have been targeted purely for financial gain. If the connections we found are accurate, this is yet another example of the Lazarus group turning its attention and considerable malicious arsenal to profiteering. Banks and other financial institutions need to fortify their defenses before it's too late," said Seongsu Park, Senior Security Researcher at Kaspersky Lab's Global Research and Analysis Team (GReAT).

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jul 11 2017 | 1:57 PM IST

Next Story