Year2010 |
MonthApril |
Reference number20100401 |
Impact areaShore |
Incident locationSeoul |
Incident countrySouth Korea |
Victim countryJapan, South Korea |
Victim identityHyundai Merchant Marine |
Victim TypeShipping Company |
MethodMalware |
Attacker countryNorth Korea |
Hyundai Merchant Marine hit by backdoor entry Fucobha from April 2010 to 2013. The North Korean attackers relied on spear-phishing and exploits for known vulnerabilities. During the operation, the attackers were using the “Icefog” backdoor set (also known as “Fucobha”). "Icefog" is a small yet energetic APT group. Victims remain infected for months or even years and attackers are continuously exfiltrating data. It was a cyber-espionage campaign, named Kimsuky. Compromising the supply chain. Targeting government institutions, military contractors, maritime and shipbuilding groups, telecom operators, satellite operators, industrial and high technology companies and mass media. The intent of the attack was data theft., extracting documents, email account credentials as well as passwords allowing access to resources within the network.