Remote Control Malware Targets South Korean Company’s Large Machine & Equipment Design Files

August 6, 2024

INCIDENT

In April 2024, the North Korean hacking organization Andariel exploited vulnerabilities of the VPN information security software used by targeted construction and machinery companies to replace update files in their systems with malware.

In addition to the VPN products, Andariel also exploited vulnerabilities in server security products. The threat actors were able to distribute remote control malware DoraRAT with the aim of using it to transfer large machine and equipment-related design files to the C2 server, according to South Korean intelligence.

Incident Date

April 15, 2024

Location

South Korea

Estimated Cost


No cost values disclosed.

Type of Malware

No Malware identified

Threat Source