More Companies being Targeted by Ransomware! Cases of Ransomware Attacks Against Company Systems

The number of cyberattacks targeting companies is increasing day by day. Just this May, the United States’ largest private pipeline company was attacked by ransomware, resulting in the shutdown of the entire pipeline facility. A well-known domestic delivery platform company also suffered from a ransomware attack, affecting hundreds and thousands of stores and delivery riders. According to a press release [1] reported by the Ministry of Science and ICT, the number of ‘Reports on Domestic Ransomware Cases for Recent Three…

CryptBot Info-stealing Malware Distributed Through Phishing Sites

The ASEC analysis team previously introduced a phishing site distributing malware disguised as a utility program. When searching the name of the utility program with a Google search keyword, the malware is shown relatively on the top list. It is being actively distributed even now, and the infection process has been changing continually. In this post, the team will explain the infection process of the recently distributed malware file which is globally known as CryptBot. Figure 1 and Figure 2 show…

APT Attacks on Domestic Companies Using Library Files

Recently, there have been continuous attacks targeting domestic companies. Most of the malicious files collected from the companies’ breached systems have been dynamic library (DLL) files, but the files used in the attacks this time are different from general DLL files. The collected files had their normal libraries modified maliciously through a variety of methods. It has not been found how the malicious files were created in the system and what the initial attack path was. Also, due to the…

Malware Disguised as Food Delivery App Being Distributed

On May 10, the ASEC analysis team confirmed that an attacker has been distributing malware in the disguise of a food delivery app, in time with the recent surge in consumption of delivery food due to COVID-19. I’d like to order app.zip (name of the compressed file) I’d like to order app\marketing.docx (XML External document malware within compressed file) I’d like to order app\changes.docx (XML External document malware within compressed file) (The filename used in the discovered malicious zip file…

ASEC Weekly Malware Statistics (May 17th, 2021 – May 23rd, 2021)

The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from May 17th, 2021 (Monday) to May 23rd, 2021 (Sunday). For the main category, info-stealer ranked top with 75%, followed by RAT (Remote Administration Tool) malware with 19.3%, downloader with 3.6%, and ransomware with 2.1%. Top 1 – AgentTesla AgentTesla was ranked first place with 27.9%. It is an info-stealer malware that leaks user…