logo

FBI: Destructive Malware Used Korean Language Packs

ID: 537e9e6b-8a10-5cd5-b2a3-30212bd157f5

STIX ID: report--537e9e6b-8a10-5cd5-b2a3-30212bd157f5

Feed Name: Security Ledger

Threat Score
80/100

Date Published: 2014-12-02

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The FBI issued a FLASH warning describing a targeted destructive malware attack that deployed downloader/dropper modules and a disk‑wiping component (identified as igfxtrayex.exe) capable of overwriting the MBR and data files; the malware beaconed to hard‑coded IPs and contained configuration files from systems using Korean language packs, prompting a possible DPRK linkage and inclusion of IoCs (file names, IPs, hostnames).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.