News North Korea exploits Itaewon tragedy for zero-day malware attack: GoogleResearchers say ScarCruft used deadly event as lure for phishing campaign targeting Internet Explorer vulnerability North Korean hackers used the deadly crush in Seoul’s Itaewon district as a lure in a malicious phishing campaign, researchers said Wednesday, seeking to exploit a zero-day vulnerability against computers running Internet Explorer (IE). According to a blog post from Google’s Threat Analysis Group (TAG), users in South Korea began receiving suspicious rich text format (RTF) documents disguised as a press release about the tragedy on Oct. 31, just two days after more than 150 people lost their lives in the bustling nighttime district. When opened, the file fetches additional code from the web to © Korea Risk Group. All rights reserved. |