Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 11th, 2012, 13:10 GMT · By

BLOG

Russian Space Research Industry Targeted by Cybercriminals Possibly from Korea

SHARE:

Adjust text size:


Word document used as bait in campaign against various Russian industries Enlarge picture - Word document used as bait in campaign against various Russian industries
Cyber espionage is highly common these days. To sum it all up, China is suspected of spying on the US, the US is accused of spying on France, and everyone is throwing the blame on Iran.

However, a new cybercriminal campaign, identified by experts from security firm FireEye, involves two other interesting actors: Russia and Korea.

The researchers have discovered an advanced persistent threat (APT) that targets organizations from various Russian industries, including space research, education, information and telecommunication.

It appears that the attackers are attempting to steal various pieces of sensitive information from their targets by tricking them into installing malware disguised as an innocent-looking Word document.

FireEye believes that Korea might be behind this operation for various reasons. For one, the SMTP mail and the command and control servers used by the malware are located in Korea (it’s not specified which Korea).

Furthermore, the fonts from the bait document are Batang and KP CheongPong, which are also Korean. Moreover, there are several other clues which point to the fact that the masterminds of the operation are native Korean speakers.

TELL US WHAT YOU THINK:

1,231 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Exforel Backdoor Implemented at NDIS Level to Be More Stealthy

Saudi Aramco: Insiders Didn’t Help Hackers Breach Our Systems

Hackers Encrypt Australian Medical Center Data, Demand $4,000 (€3,100) Ransom

Searching for “Windows Android Drivers” Can Lead You to Malware-Laden Sites

Malware Disguised as Trend Micro Product Spreads Bitcoin Miner

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM