Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

North Korean Hackers Steal Defense Files from South

North Korean hackers managed to steal thousands of records from private firms and state agencies in the South including defense industry information and files from Korean Air, Seoul police said Monday.

North Korean hackers managed to steal thousands of records from private firms and state agencies in the South including defense industry information and files from Korean Air, Seoul police said Monday.

The hacking originated from 16 servers based in the North’s capital Pyongyang, police said, adding the North had stolen more than 42,000 internal records.

The North gained access to the internal systems of the firms and agencies at some point after hacking in 2014 into computer management software developed by a Seoul IT firm, according to the police.

North Korea Cyber Attacks

The breach was discovered earlier this year.

The hackers also planted 33 types of malicious code into the computers in an apparent bid to use them as “zombie” machines to launch future cyberattacks on other organizations in the South, it said.

The companies that were hacked include South Korea’s flagship air carrier Korean Air and SK Networks, a sister company of South Korea’s top wireless operator, SK Telecom, Yonhap news agency said.

“We worked with the organizations that were targeted to recover the lost records and fortify their computer security to prevent further infiltration,” the police said in a statement.

Some of the stolen records however contained information about the defense industry or network data essential to stage cyberattacks, it added.

Advertisement. Scroll to continue reading.

The records include designs of military aircraft and Internet facilities at South Korean army barracks, according to the Yonhap.

Police added that some of the 16 servers in Pyongyang had the same IP addresses as those that had staged a crippling cyberattack on Seoul’s banks and TV broadcasters in 2013.

Seoul has in recent years blamed the North’s hackers for a series of cyberattacks on military institutions, banks, state agencies, TV broadcasters, media websites and a nuclear power plant.

The attack in March 2013 left the websites and tens of thousands of computers at several TV stations and banks paralyzed for hours.

Pyongyang has angrily denied involvement in the attacks and accused Seoul of spreading fabrications aimed at slandering its leader.

The North operates an army of more than 1,000 hackers who stage hacking or cyberattacks targeting Seoul’s major institutions or key officials, according to the South’s spy agency.

Related ReadingSouth Korea Says North Hacked Phones of Key Officials

Related Reading: South Korea Accuses North of Cyber-attacks on Nuclear Plants

Related Reading: South Korea Nuclear Plants Stage Drill Against Cyber Attack

Related Reading: South Korea’s ‘Top Gun’ Cyber Warriors

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...