B. Korea: planted a backdoor to South Korea's most famous text editor

linked to North Korea exploited a backdoor in Hangul, the most popular word processor widely used in South Korean government offices. The online battle against espionage is taking place globally!

backdoor cuts

According to the company's research , the attackers used a known vulnerability (CVE-2015 – 6585), which has been patched as of Monday, September 7.

Το zero-day exploit βρισκόταν σε ένα έγγραφο τύπου .hwpx (παρόμοιο με .docx που χρησιμοποιείται από το Microsoft Office), το οποίο εκμεταλλευόταν σφάλματα στον επεξεργαστή κειμένου Hangul (ο διασημότερος text in Korea, Microsoft's equivalent of Word) to open a backdoor in the software.

According to the security company FireEye, this backdoor, called HANGMAN, is capable of stealing files and sending them to a Command & Control Server, while also being able to download new files to the victim's computer.

The Hangman backdoor was also very well designed, as it used SSL connections to encrypt its communications with the C&C Server (management and control server), hiding data transfer from prying eyes.

Targeting South Korea's own proprietary word processing software clearly indicates a particular interest in South Korea, based on the similarities between the code used and the infrastructure, FireEye Intelligence estimates that this activity is possibly related to agents in the North Korean.

For more and in-depth technical details regarding its distribution s, you can download the full efireEye report (PDF).

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).