South Korean cyberattacks used hijacked patch management accounts

Not our servers, says antivirus vendor AhnLab

The attackers who unleashed devastating hard-drive wiping malware on South Korean TV stations and banks earlier this week executed at least part of the attack by hijacking the firms' patch management admin accounts, the software vendor involved has said.

According to South Korean antivirus company AhnLab, the 20 March attacks used stolen IDs and passwords for its Patch Manager software to distribute the malware to an unknown number of the 32,000 PCs affected inside the victim firms, including the Munhwa, YTN, Korea Broadcasting System (KBS) TV stations, and the Shinhan, Jeju and Nonghyup banks.

These systems were under the control of the organisations involved and not AhnLab itself, the company emphasised.

"Contrary to early reports, no security hole in any AhnLab server or product was used by the attackers to deliver the malicious code," AhnLab said in a statement.

The fact that several of the firms were using the company's software was coincidence; as a local ISV, AhnLab enjoyed a high market share in the country for its security products, the company said.

Exactly how the attackers were able to get hold of the credentials and co-ordinate the attack remains a mystery but indicated that it had been planned for some time, AhnLab director of marketing and business development Brian Laing said.

Some have suggested that the attackers had gained control of at least some of the target PCs using an undetected botnet system, but this remains speculation.

Laing agreed that the attack had attempted to shut down AhnLab's antivirus client as well as that of a second popular South Korean vendor, Hauri.

Claimed by the mysterious 'Whois' team, the attack attempted - and succeeded - in causing maximum disruption by overwriting the Master Boot Record (MBR) on affected PCs after a reboot.

This is remarkably similar to the 'Shamoon' attack last year on Saudi Arabia's oil industry, which also affected about 30,000 systems after executing its disk-wiping routine at a pre-defined moment.

One unusual element of the South Korean malware, dubbed 'Jokra' by Symantec, is that despite being Windows-oriented it contains a script that could be used to wipe Linux systems.

"The included module checks Windows 7 and Windows XP computers for an application called mRemote, an open source, multi-protocol remote connections manager," a Symantec analysis reported.

Suspicions have fallen on North Korea or another state as the culprit simply because of the resources necessary to pull of such a targeted and highly-crafted attack.

The fact that victims were solely South Korean has also reinforced this view. As with so many cyberattacks, evidence is and will probably remain, thin on the ground.

Join the CSO newsletter!

Error: Please check your email address.

Tags symantecsecurity

More about LinuxSymantec

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by John E Dunn

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place