FBI: Destructive Malware Used Korean Language Packs
ID: 537e9e6b-8a10-5cd5-b2a3-30212bd157f5
STIX ID: report--537e9e6b-8a10-5cd5-b2a3-30212bd157f5
Feed Name: Security Ledger
Threat Score
The FBI issued a FLASH warning describing a targeted destructive malware attack that deployed downloader/dropper modules and a disk‑wiping component (identified as igfxtrayex.exe) capable of overwriting the MBR and data files; the malware beaconed to hard‑coded IPs and contained configuration files from systems using Korean language packs, prompting a possible DPRK linkage and inclusion of IoCs (file names, IPs, hostnames).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
