DPRKurious: Is North Korea Really Behind Cyber Attacks On The South?
ID: 8f6918dc-d08d-57a8-a778-311cc54ed852
STIX ID: report--8f6918dc-d08d-57a8-a778-311cc54ed852
Feed Name: Security Ledger
A widespread wiper campaign hit South Korean banks, broadcasters and other firms, erasing master boot records and attached/networked drives and displaying defacements claiming 'Hacked by Whois Team'. Analysts identified the malware (Trojan.Jokra) and MBR overwrite markers ('HASTATI', 'PRINCIPES'), noted AV-killing behavior and links to the Gondad exploit kit and Chinese infrastructure, and reported South Korean officials' strong suspicion of DPRK involvement while emphasizing attribution remains inconclusive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
