Symantec says Trojan.Korhigh is capable of deleting certain file types

Jun 28, 2013 12:25 GMT  ·  By

After the recent cyberattacks on South Korea, experts noted that the computers used to launch the attacks against government organizations displayed a wallpaper that attributed the attack to the Anonymous movement.

Experts have determined that the attacks are the work of a group called DarkSeoul, which has been launching similar operations against South Korea for the past four years.

According to Symantec, a new piece of malware designed to wipe the disks of infected computers has been identified in the latest series of attacks.

Dubbed Trojan.Korhigh, the malware is capable of changing the user passwords of compromised computers to “highanon2013.” In addition, it’s also capable of deleting certain files, such as executable files, web pages, and media files.

The Trojan is also designed to change the wallpaper of the infected device with the Anonymous image (see screenshot).