North Korean hacking group Lazarus behind cyber attack last year: Police

정주희 2023. 4. 18. 16:57
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

Major North Korean hacking group Lazarus was behind a cyberattack last year that targeted as many as 10 million users of a banking security app, the police announced Tuesday. The National Police Agency confirmed that the Lazarus Group...
A member of the National Police Agency announces its recent findings on a cyberattack by North Korea that targeted as many as 10 million users last year, at the police precinct in Seodaemun District, western Seoul, on Tuesday. [YONHAP]

Major North Korean hacking group Lazarus was behind a cyberattack last year that targeted as many as 10 million users of a banking security app, the police announced Tuesday.

The National Police Agency confirmed that the Lazarus Group, a North Korean state-sponsored hacking organization, was behind the cyberattacks on the computers used by 61 organizations in Korea including public institutions and defense industry organizations last November.

They launched what experts call a watering hole attack, which targets a specific group of users by infecting websites that they are likely to visit.

The group was found to have hacked into Initec, a major local financial security provider, in April 2021 and tampered with one of its software products.

If a user who downloaded this banking security application onto their computer visited infected websites, which included those of some media companies, their computers would immediately be implanted with a malware, according to the police.

As many as 10 million computers across 61 organizations were estimated to have downloaded the financial security software.

Authorities said that the group, after infecting computers and seizing control over them, would have tried to expand the cyberattack using the computers’ networks.

Damage was minimal. however, because the attack was detected in its early stages, said police. The group was able to infect 207 computers.

The U.S. Treasury Department suspects the Lazarus Group has stolen at least $455 million last year through cyber attacks.

BY ESTHER CHUNG [chung.juhee@joongang.co.kr]

Copyright © 코리아중앙데일리. 무단전재 및 재배포 금지.

이 기사에 대해 어떻게 생각하시나요?