Trojan update fingered for massive South Korean breach

Breach could blow out by millions.

Software company ESTsoft was responsible for a massive compromise of some 35 million South Koreans last month after it pushed out malware to some of the country’s largest web companies.

Unidentified hackers uploaded malware to an EFTsoft server through a common, vulnerable DLL module that the company used to send updates to its 25 million subscribers.

The malware and was subsequently uploaded to websites owned by SK Communications, including social networking site Cyworld.

Public notice

South Korea’s National Police Agency pinned the breach on the software provider, which operates popular anti-virus product AIYak.

An advisory issued by ESTsoft said hackers had uploaded a backdoor trojan dubbed SOGU, rated as highly dangerous by Trend Micro.

The software company had pushed out a patch and said it was working with South Korean law enforcement to investigate the breach.

A customer backlash had already begun. The Korea JoonGang Daily reported that the country’s biggest web portal NHN ordered that ESTsoft programs be deleted.

Other internet and web services providers said they were on the lookout for breaches.

The National Police Agency said it was unknown if the compromise also affected consumers using the anti-virus program.

If so, it could dramatically increase the number of people compromised in the attack by tens of millions.

The Malaysian News Agency reported that a South Korean man had filed damages against SK Communications for $2700 in compensation for the breach of his personal information.

Copyright © SC Magazine, Australia

Trojan update fingered for massive South Korean breach
ALtools character.
Company/Organisation

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
ALtools character.
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read