Remote Control Malware Targets South Korean Company’s Large Machine & Equipment Design Files
INCIDENT
In April 2024, the North Korean hacking organization Andariel exploited vulnerabilities of the VPN information security software used by targeted construction and machinery companies to replace update files in their systems with malware.
In addition to the VPN products, Andariel also exploited vulnerabilities in server security products. The threat actors were able to distribute remote control malware DoraRAT with the aim of using it to transfer large machine and equipment-related design files to the C2 server, according to South Korean intelligence.
