South Korea hacks blamed on 'Dark Seoul Gang'

Summary:A four-year hacking spree inflicted on South Korea is apparently down to a single hacking group called the "Dark Seoul Gang."

Research conducted by U.S. security software maker Symantec Corp has uncovered a hacking campaign against South Korea dating back four years.

While reviewing malicious software code, Symantec researchers joined the dots and concluded that a number of cyberattacks conducted on the country originate from a single group called the "Dark Seoul Gang." According to Reuters, chunks of code identified are identical to evidence found in "significant" attacks over the time period, first discovered in 2009.

Eric Chien, technical director with Symantec Security Response, says that the evidence does not point to the identity of the group members, but estimates there are between 10 and 50 members due to the code's sophistication and complexity of their attacks.

In addition, the Dark Seoul Gang are "extremely well-coordinated" when conducting hacking campaigns.

According to the security firm, the hacking group is responsible for attacks including the Jokra attacks in March 2013 that wiped numerous computer hard drives at South Korean banks and broadcasting facilities, as well as the attacks on the country's financial companies in May 2013.

Screen Shot 2013-06-27 at 11.08.20

The Dark Seoul Gang's activities often include multi-stage, coordinated attacks against South Korean targets, including overwriting discs with political strings and the use of destructive payloads, DDoS attacks and command-and-control structures.

On Tuesday, the day that marked the beginning of the Korean war 63 years ago, South Korea suffered another round of cyberattacks which took down governmental and private sites including the presidential Blue House site. In addition, hackers say they were able to steal and publicly share the details of over 2 million South Korean ruling-party members and 40,000 U.S. troops, some of which are currently stationed in the country.

North Korea has previously been blamed for launching cyberattacks against its southern counterpart, but has denied such allegations. In response, the country has said it has also been a victim of cyber warfare. Symantec says:

"Symantec expects the DarkSeoul attacks to continue and, regardless of whether the gang is working on behalf of North Korea or not, the attacks are both politically motivated and have the necessary financial support to continue acts of cybersabotage on organizations in South Korea."

Topics: Security, Malware

About

Charlie Osborne, a medical anthropologist who studied at the University of Kent, UK, is a journalist, freelance photographer and former teacher. She has spent years travelling and working across Europe and the Middle East as a teacher, and has been involved in the running of businesses ranging from media and events to B2B sales. Charli... Full Bio

zdnet_core.socialButton.googleLabel Contact Disclosure

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Related Stories

The best of ZDNet, delivered

You have been successfully signed up. To sign up for more newsletters or to manage your account, visit the Newsletter Subscription Center.
Subscription failed.