IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Stolen logins used to distribute malware in South Korea attacks

Security vendor AhnLab claims credentials were used to access patch management systems and distribute malware.


Security vendor AhnLab has confirmed that stolen login details were used to carry out cyber attacks against South Korean banks and broadcasters last week.

As reported by IT Pro last week, hackers brought down several broadcasters and major banks in South Korea, in a series of attacks that have been linked to North Korea and China.

It is thought the attacks affected 32,000 servers managed by the banks and broadcasters.

A malware analysis by security vendor AlienVault said the attack had been caused by a piece of code that overwrites the master boot record and stops computers restarting after a reboot.

But, at the time of last week's report, the firm was unable to shed any light on how the malware gained access to the systems.

However, South Korea-based security vendor AhnLab has now claimed the hackers obtained user IDs and passwords to deliver the malware during some of the attacks.

"The credentials were used to gain access to individual patch management systems located on the affected networks," said the company in a statement.

"Once the attackers had access to the patch management system they used it to distribute the malware much like the system distributes new software and updates."

Speaking to IT Pro, Simon Edwards, regional manager for the UK at AhnLab, confirmed the attackers were able to use the logins to infiltrate his firm's patch management tools.

"There was no compromise of our own systems at any point, but they managed to get our user names and passwords from somewhere," he added.

The company also claims the malware can be detected in real-time and deleted using its multi-dimensional protection technology.

Featured Resources

Meeting the future of education with confidence

How the switch to digital learning has created an opportunity to meet the needs of every student, always

Free Download

The Total Economic Impact™ of IBM Cloud Pak® for Watson AIOps with Instana

Cost savings and business benefits

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

Technology reimagined

Why PCaaS is perfect for modern schools

Free Download

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

7 Jun 2022
Attracting and retaining talent through training

Attracting and retaining talent through training

13 Jun 2022
Swift exit: How the world cut off Russian banks

Swift exit: How the world cut off Russian banks

24 Jun 2022