South Korea warns of phishing emails and watering-hole attacks led by state-backed hackers
South Korea’s National Intelligence Service (NIS), the Korea National Police Agency (KNPA), the Korea Internet and Security Agency (KISA), the Financial Security Institute (FSI) and a public-private joint analysis consultative body (AhnLab, S2W, Enki Whitehat, Plainbit) warned of threats from hacking emails and watering-hole attacks by state-backed hacking groups. To minimise damage, they recommended information on attack methods, types of damage and mitigation steps.
A watering-hole attack is a method in which attackers hack a legitimate site, hide malware and infect visitors simply through access.
The NIS said it has repeatedly confirmed cases in which state-backed hacking groups send phishing emails disguised as resumes or job offers and induce recipients to open them, infecting them with malware. It also said cases continue to be confirmed in which the groups hack widely used internet news and hospital sites, as well as small websites with weak security management, and use them as a foothold to spread malware.
This attack method can combine with vulnerabilities in security software installed long ago on a user’s computer, allowing infection simply by visiting a website. Hacking groups send hacking emails with content likely to interest recipients, disguised as recruitment or donations, attaching malicious links or malicious files.
They also plant malware on legitimate websites they have already hacked and send emails with the site address included as a link in the body. Because the recipient sees it as a normal website, the recipient clicks without suspicion and becomes infected with malware.
For companies, if damage occurs, attackers can exfiltrate internal documents, customer information and business materials and take them hostage to threaten, leak and spread damage, requiring caution.
The related agencies urged people to report suspected state-backed hacking incidents and the discovery of similar cases.
KISA’s Internet Incident Response Center, the Financial Security Institute’s incident response division and the NIS National Cyber Security Center (NCSC) are paying reporting rewards for valuable reports on cyber threats.