Hyundai Merchant Marine hit by backdoor entry Fucobha

Year

2010

Month

April

Reference number

20100401

Impact area

Shore

Incident location

Seoul

Incident country

South Korea

Victim country

Japan, South Korea

Victim identity

Hyundai Merchant Marine

Victim Type

Shipping Company

Method

Malware

Attacker country

North Korea

Summary:

Hyundai Merchant Marine hit by backdoor entry Fucobha from April 2010 to 2013. The North Korean attackers relied on spear-phishing and exploits for known vulnerabilities. During the operation, the attackers were using the “Icefog” backdoor set (also known as “Fucobha”). "Icefog" is a small yet energetic APT group. Victims remain infected for months or even years and attackers are continuously exfiltrating data. It was a cyber-espionage campaign, named Kimsuky. Compromising the supply chain. Targeting government institutions, military contractors, maritime and shipbuilding groups, telecom operators, satellite operators, industrial and high technology companies and mass media. The intent of the attack was data theft., extracting documents, email account credentials as well as passwords allowing access to resources within the network.

Reference URL

https://securelist.com/the-icefog-apt-a-tale-of-cloak-and-three-daggers/57331/
https://www.theregister.com/2013/09/26/icefog_hit_and_run_apt_japan_south_korea/
https://securelist.com/it-threat-evolution-q3-2013/57885/
https://www.theguardian.com/technology/2013/sep/11/north-korean-hackers-cyber-espionage
https://www.zdnet.com/article/ancient-icefog-apt-malware-spotted-again-in-new-wave-of-attacks/ https://securityaffairs.com/86826/apt/icefog-apt-group-return.html