FacebookInstagramTwitterContact

 

South Korea: World Scout Jamboree Disaster Blamed On Government           >>           Ben-Gvir, Israeli Far-Right Minister, In Car Accident           >>           Pentagon To 'Rush' Patriot Missiles To Ukraine In $6bn Package           >>           Major Gaza Protests At US Universities           >>           Burkina Faso Suspends BBC Over HRW Report On Alleged Mass Killings           >>           AIPA-FAO-IISD Joint Workshop           >>           Tesla Autopilot Recall To Be Probed By US Regulator           >>           ISO 9001:2015 Certificate Award           >>           Why Green Steam Is A Hot Issue For Business           >>           Use a Plot of Land for Planting           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


North Korean Hackers Used An IE Vulnerability To Target South Koreans After Halloween Tragedy


Chris Jung/NurPhoto via Getty Images

 


 December 8th, 2022  |  09:52 AM  |   693 views

NORTH KOREA

 

Google and Microsoft worked quickly to patch the zero-day.

 

In the aftermath of the Itaewon Halloween crowd crush that killed at least 158 people, North Korea’s APT37 state-sponsored hacking group took advantage of a previously unknown Internet Explorer vulnerability to install malware on the devices of South Koreans who were trying to find out about the tragedy, according to Google’s Threat Analysis Group. The team became aware of the recent attack on October 31st after multiple South Koreans uploaded a malicious Microsoft Office document to the company’s VirusTotal tool.

 

APT37 took advantage of national interest in the Itaewon tragedy by referencing the event in an official-looking document. Once someone opened the doc on their device, it would download a rich text file remote template that would, in turn, render remote HTML using Internet Explorer. According to Google, this is a technique that has been widely used to distribute exploits since 2017, as it allows hackers to take advantage of vulnerabilities in Internet Explorer even if someone isn’t using IE as their default web browser.

 

The JavaScript vulnerability APT37 took advantage of allowed the group to execute arbitrary code. Google informed Microsoft of the zero-day on the same day it became aware of it. On November 8th, Microsoft released a software update to address the exploit. “We’d be remiss if we did not acknowledge the quick response and patching of this vulnerability by the Microsoft team,” Google said.

While the TAG team didn’t get a chance to analyze the final malware APT37 hackers attempted to deploy against their targets, it notes the group is known for using a wide variety of malicious software, including ROKRAT, BLUELIGHT and DOLPHIN. “TAG also identified other documents likely exploiting the same vulnerability and with similar targeting, which may be part of the same campaign,” the team added.

 

This isn’t the first time Google’s Threat Analysis Group has thwarted an attack by North Korean hackers. At the start of 2021, the team detailed a campaign that targeted security researchers. More recently, the team worked with the Chrome team to address a vulnerability that was used by two North Korean hacking cadres to execute remote code.

 


 

Source:
courtesy of ENGADGET

by Igor Bonifacic

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

South Korea: World Scout Jamboree Disaster Blamed On Government

 2024-04-27 02:37:15

Tesla Autopilot Recall To Be Probed By US Regulator

 2024-04-27 01:55:10