Saturday, September 30, 2023
manilastandard.net
ADVERTISEMENT
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
    • Young Life
  • Special Pages
    • Pets
    • Tech
      • Gadgets
      • Computers
      • Business
      • Tech Plus
    • On the Road
      • Sedan
      • SUV
      • Truck
      • Bike
      • Accessories
      • Motoring Plus
      • Commuter’s Corner
    • Home & Design
      • Residential
      • Commercial
      • Construction
      • Interior
    • Spotlight
    • Cravings
    • Environment & Sustainability
    • Agriculture
    • Pop.Life
      • Newsmakers
      • Hangouts
      • A-Pop
      • Post Its
      • Performances
      • Malls & Bazaars
      • Hobbies & Collections
    • Events
      • Seminars
      • Exhibits
      • Community
    • Biyahero
      • Travel Features
      • Travel Reels
      • Travel Logs
    • Gallery
      • Photos
      • Videos
  • Advertise with Us
No Result
View All Result
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
    • Young Life
  • Special Pages
    • Pets
    • Tech
      • Gadgets
      • Computers
      • Business
      • Tech Plus
    • On the Road
      • Sedan
      • SUV
      • Truck
      • Bike
      • Accessories
      • Motoring Plus
      • Commuter’s Corner
    • Home & Design
      • Residential
      • Commercial
      • Construction
      • Interior
    • Spotlight
    • Cravings
    • Environment & Sustainability
    • Agriculture
    • Pop.Life
      • Newsmakers
      • Hangouts
      • A-Pop
      • Post Its
      • Performances
      • Malls & Bazaars
      • Hobbies & Collections
    • Events
      • Seminars
      • Exhibits
      • Community
    • Biyahero
      • Travel Features
      • Travel Reels
      • Travel Logs
    • Gallery
      • Photos
      • Videos
  • Advertise with Us
No Result
View All Result
manilastandard.net
No Result
View All Result
Home Technology Tech Plus

INTEL HUNT: Southeast Asia, Korea remain main targets of Korean-speaking APT groups

Manila StandardbyManila Standard
November 4, 2019, 4:33 pm
in Tech Plus
Reading Time: 5 mins read
A A
Share on FacebookShare on TwitterShare on Email

An Android malware disguising as a mobile messenger or as a cryptocurrency app targeting individual cryptocurrency trader and organization, an infamous APT (Advanced Persistent Threat) group continuously changing its tools to compromise banks, and a subgroup of Lazarus exploiting CVE-2017-10271 to infiltrate a cybersecurity vendor.

INTEL HUNT: Southeast Asia, Korea remain main targets of Korean-speaking APT groups

Different hacking groups targeting diverse organizations but all are Korean-speaking actors waging threats in the Korean peninsula and in the Southeast Asia region. These and more findings from Kaspersky’s APT Trends Reports Q3 2019.

KONNI and Korea’s cryptocurrency related business

Among the new activities monitored by Kaspersky researchers is an Android malware camouflaging as a mobile messenger or as cryptocurrency-related applications.

After working closely with Korea’s local CERT in taking down the attacker’s server, Kaspersky was able to investigate the new malware and to discover its relation to KONNI. KONNI is a Windows malware strain that has been used in the past to target a human rights organization and personalities with an interest in Korean Peninsula affairs.

It is also known for targeting cryptocurrencies by implementing full-featured functionalities to control an infected Android device and steal personal cryptocurrency using these features.

Stealthy BlueNoroff and banks in Southeast Asia

Kaspersky has also monitored BlueNoroff, the financial-arm of the infamous APT group Lazarus, infecting a bank in Myanmar during the third quarter of 2019.

With the prompt alert the global cybersecurity company has sent to the concerned bank, researchers were able to obtain valuable information on how the attackers move laterally to access high value hosts, such as those owned by the bank’s system engineers interacting with SWIFT.

Kaspersky’s investigation also uncovered the tactics BlueNoroff has been implementing to evade detection, such as using and continuously changing its Powershell script. The group also employs highly sophisticated malicious software which can run as passive or active backdoor, or even a tunnelling tool, depending on the command line parameters.

Andariel APT and South Korean security vendor

Another sub-group of Lazarus, Andariel APT group, has been conducting new efforts to build a new C2 infrastructure targeting vulnerable Weblogic servers through exploiting CVE-2017-10271. This tactic has proven effective after a successful breach by the attackers who implanted malware signed with a legitimate signature belonging to a South Korean security software vendor. The malicious signature has been revoked through the quick response of South Korean CERT.

Traditionally focused on geopolitical espionage and financial intelligence in South Korea, Andariel is also using a brand new type of backdoor dubbed as ApolloZeus. This complex and discreet backdoor uses a relatively large shellcode in order to make analysis difficult.

Based on Kaspersky’s investigation of the artifact found, the group’s attack is an early preparation stage for a new campaign.

"Targeted attacks against financial institutions combine sophisticated techniques – that were previously seen only in APT attacks – with typical criminal infrastructures used to launder the stolen goods. In Q3, we've seen advanced threat actors such as Andariel and Lazarus' BlueNoroff arm attempting to breach not only banks, but investment companies and cryptocurrency exchanges, among others. We advise all companies in APAC to be vigilant and take precautions to guard against such attacks,” says Costin Raiu, Director of Global Research & Analysis Team at Kaspersky.

DADJOKE and geopolitical entities in Southeast Asia

Aside from the active Korean-speaking APT groups in Q3 2019, Kaspersky has also observed a recent campaign utilizing a piece of malware referred to by FireEye as DADJOKE hunting intelligence in Southeast Asia.

Researchers have monitored the use of this malware in a small number of campaigns during the beginning of the year against government, military, and diplomatic entities in the Southeast Asia region. The latest known movement of this malware was detected last August 29 involving a select few individuals working for a military organization.

“We have highlighted in our Q2 APT Report the increased attention Korean-focused APT campaigns have been giving towards different organizations and personalities in Southeast Asia and Korea. True to our prediction, we have monitored several malicious activities of Korean-speaking APT groups and new malware in both regions from July to September this year. Our observations suggest that most of them are intelligence-hungry, both for financial and geopolitical secrets,” comments Seongsu Park, senior security researcher at Kaspersky.

The Q3 APT Trends report summarizes the findings of Kaspersky’s subscriber-only threat intelligence reports, which also include Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malware-hunting. For more information, please contact: [email protected] .

The full Kaspersky Q3 APT Trends Report is available here: https://securelist.com/apt-trends-report-q3-2019/94530/.

Tags: advanced persistent threatAPT Trends Reports Q3 2019cybersecurityKaspersky
ADVERTISEMENT
Manila Standard

Manila Standard

Related Posts

Man on mission: Lee champions fintech in PH and beyond

byManila Standard
September 29, 2023, 6:10 pm
0
8
Man on mission:  Lee champions fintech in PH and beyond

“IF it sounds too good to be true, it probably is too good to be true.” Commissioner Kelvin Lee of...

Read more

Smart unveils Super Value Deals for prepaid subscribers

byManila Standard - Tech
September 29, 2023, 5:57 pm
0
8
Smart unveils Super Value Deals for prepaid subscribers

Smart Prepaid is making it so much easier for subscribers to enjoy more data and flexibility to cover all their...

Read more

Experience cutting-edge HVAC Solutions with LG, Hi-M Solutek

byManila Standard - Tech
September 29, 2023, 5:51 pm
0
8
Experience cutting-edge HVAC Solutions with LG, Hi-M Solutek

SM North EDSA, a prominent member of the Philippines' largest mall chains, is making waves in the world of cooling...

Read more

Globe returns as co-presenter for Cosplay Mania, celebrates anime, cosplay fans

byManila Standard - Tech
September 29, 2023, 2:27 pm
0
8
Globe returns as co-presenter for Cosplay Mania, celebrates anime, cosplay fans

Globe returns as the title sponsor for Cosplay Mania, Asia's premier Japanese content convention, its second consecutive year of hosting...

Read more

Cebuana Lhuillier Bank joins forces with Temenos to revolutionize financial services for Filipinos

byManila Standard - Tech
September 28, 2023, 3:14 pm
0
8
Cebuana Lhuillier Bank joins forces with Temenos to revolutionize financial services for Filipinos

Formalizing the partnership (from left) Nick Edwards, Deputy Regional Director APAC and General Manager, ASEAN of Temenos; Philippe Andre Lhuillier,...

Read more

Converge: Answering the call of digitalization

byManila Standard - Tech
September 28, 2023, 12:36 pm
0
8
Converge: Answering the call of digitalization

Converge CEO and Co-Founder Dennis Anthony Uy   “Digitalization is the call of today; not the call of the future—but...

Read more

Print Edition

View More

Recent Posts

  • Blood drive draws 100 donors at SM Camanava malls
  • Discover Italy
  • PH not backing down over maritime rights
  • ‘China spending billions to spread disinformation’
  • PBBM orders collection of unauthorized ‘pass-through fees’ suspended
  • Not chips or cookies
  • ‘No Hunger’ push starts in Siargao
  • ‘Whole-of-drugnation program to fight drugs needed’

Advertisement

Latest News

Not chips or cookies

byManila Standard
September 30, 2023, 1:13 am
0
8
‘No Hunger’ push starts in Siargao

Authorities display potato chip and cookie cans that contain packs of cocaine, part of a stash of 14.36 kilos of...

Read more

‘No Hunger’ push starts in Siargao

byCharles Dantesand1 others
September 30, 2023, 1:10 am
0
8
‘No Hunger’ push starts in Siargao

The government officially kicked off its Food Stamp Program (FSP) on Friday as part of its “No Hunger” campaign, with...

Read more

‘Whole-of-drugnation program to fight drugs needed’

byJoel E. Zurbanoand1 others
September 30, 2023, 1:05 am
0
8
Marcos stresses PH ties with Japan notably in agriculture, defense, infra

President Ferdinand R. Marcos Jr. said a whole-of-nation approach is needed to rid the country of illegal drugs through prevention,...

Read more

All regions to see wage hikes before year ends—DOLE

byVito Barcelo
September 30, 2023, 1:00 am
0
8
DOLE halts December labor probes

All regions will see an increase in daily minimum wages before the year ends, the Department of Labor and Employment...

Read more

PhilHealth website, member’s portal active again

byMacon Ramos-Araneta
September 30, 2023, 12:55 am
0
8
PhilHealth expedites settling debts to hospitals by debit-credit scheme

The website and member's portal of the Philippine Health Insurance Corp. (PhilHealth) went back online yesterday after eight days of...

Read more

Advertisement

ADVERTISEMENT
Facebook Twitter Instagram Youtube

ABOUT US

Manila Standard

Manila Standard website (manilastandard.net), launched in August 2002, extends the newspaper’s reach beyond its traditional readers and makes its brand of Philippine news and opinion available to a much wider and geographically diverse readership here and overseas.

Digital Edition

In tone and content, the online edition mirrors the editorial thrust of the newspaper. While hewing to the traditional precepts of fairness and objectivity, MS believes the news of the day need not be staid, overly long or dry. Stories are succinct, readable and written in a lively style that has become a hallmark of the newspaper.

Download – Today’s Paper

Search

No Result
View All Result

6th Floor Universal Re Bldg., 106 Paseo De Roxas cor. Perea Street, Legaspi Village, 1226 Makati City Philippines

Trunklines: 832-5554, 832-5556, 832-5558

© 2021 Manila Standard - Designed and Developed by Neitiviti Studios.

No Result
View All Result
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
    • Young Life
  • Pets
  • Tech
    • Gadgets
    • Computers
    • Business
    • Tech Plus
  • ON THE ROAD
    • Sedan
    • SUV
    • Truck
    • Bike
    • Accessories
    • Motoring Plus
    • Commuter’s Corner
  • Home & Design
    • Residential
    • Commercial
    • Construction
    • Interior
  • Spotlight
  • Cravings
  • Environment & Sustainability
  • Agriculture
  • Pop.Life
    • Newsmakers
    • Hangouts
    • A-Pop
    • Post Its
    • Performances
    • Malls & Bazaars
    • Hobbies & Collections
  • Events
    • Seminars
    • Exhibits
    • Community
  • Biyahero
    • Travel Features
    • Travel Reels
    • Travel Logs
  • Gallery
    • Photos
    • Videos
  • Advertise with Us

© 2021 Manila Standard - Designed and Developed by Neitiviti Studios.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Install Manila Standard Web App

Install App