DistantNews

New 'Midnight' and 'Endpoint' Ransomware Spreading in South Korea; Attackers Impersonate IT Firms

From Hankyoreh · (7h ago) Korean Critical tone

Translated from Korean, summarized and contextualized by DistantNews.

TLDR

  • South Korean authorities have confirmed a surge in ransomware attacks targeting small and medium-sized businesses, using new strains dubbed 'Midnight' and 'Endpoint'.
  • Attackers impersonate IT maintenance firms, sending phishing emails to infiltrate systems and steal data before encrypting files and demanding payment.
  • The 'double extortion' tactic, involving data theft and threats of public release, is being used, with victims spanning manufacturing, distribution, energy, and public sectors.

South Korean cybersecurity agencies, including the National Police Agency and the Korea Internet & Security Agency (KISA), have issued a stark warning about the escalating threat of 'Midnight' and 'Endpoint' ransomware. These sophisticated attacks are specifically targeting our nation's vital small and medium-sized enterprises (SMEs), which form the backbone of our economy.

The modus operandi is particularly insidious. Cybercriminals are posing as trusted IT service providers, using deceptive emails for 'quotes, job applications, or consulting requests' to gain initial access. Once inside, they pilfer internal and account information. The second wave of attack involves impersonating the compromised IT firm to target its clients, effectively using a trusted relationship as a weapon.

The victims include many small and medium-sized manufacturers, and damage has also been confirmed in distribution, energy, and public institutions, so caution is needed across all industries.

— National Police AgencyThe National Police Agency highlighted the widespread impact of the ransomware attacks.

What makes this threat particularly alarming is the 'double extortion' method. It's not just about encrypting files; attackers are stealing data first and then demanding payment, threatening to leak sensitive information. This significantly raises the stakes for victimized companies, creating immense pressure to comply. The scope of the threat is broad, affecting not only manufacturing SMEs but also distribution, energy, and even public institutions, underscoring the need for vigilance across all sectors.

In response, the police and KISA have collaborated to develop and distribute comprehensive advisories, detailing attack methods, types, and countermeasures. This marks a significant step in proactive defense, with the police officially issuing security recommendations based on investigative intelligence. South Korea is committed to swiftly sharing threat information and bolstering our defenses against these evolving cyber threats.

We are currently investigating attacks related to this ransomware and plan to quickly share additional threat information with related agencies and companies.

— National Police AgencyThe National Police Agency stated its ongoing investigation and commitment to information sharing.
DistantNews Editorial

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.