Showing posts with label South. Show all posts
Showing posts with label South. Show all posts

Thursday, 12 September 2013

Cyberspies attack key South Korean institutions, North Korean hackers suspected

South Korean organizations that conduct research on international affairs, national security and Korean unification are under siege from cyberspies whose attack may have its origins in North Korea.

The attack campaign, which has been dubbed “Kimsuky,” involves the use of malware to steal sensitive information from these institutions and has been monitored for the past several months by researchers from antivirus vendor Kaspersky Lab.

The full list of victims remains unknown, but Kaspersky’s technical analysis suggests that organizations targeted included: the Sejong Institute, a non-profit think tank that conducts research in the areas of national security, unification, regional issues and international political economy; the Korea Institute for Defense Analyses (KIDA), a research institution whose research focuses on military planning, security and strategy, human resource development, weapon systems, and more; the South Korean Ministry of Unification which works towards the reunification of Korea and promotes inter-Korean dialogue and the Hyundai Merchant Marine, a South Korean logistics company specialized in container shipping.

“Among the organizations we counted, 11 are based in South Korea and two entities reside in China,” Dmitry Tarakanov, a malware researcher at Kaspersky Lab, said Wednesday in a blog post.

The malware used in the attack, which is now detected by Kaspersky products as Trojan.Win32.Kimsuky, communicates with attackers through a free webmail service in Bulgaria called mail.bg. The malware connects to the webmail interface and authenticates with hardcoded credentials for specific mail.bg accounts.

It then checks the inbox folder for messages that have subject lines indicating certain commands from attackers. Those emails can also contain encrypted attachments, which are encrypted malicious executable files that serve as updates or additional components for the malware.

It’s not clear how attackers distribute the Kimsuky Trojan horse program to their targets, but spear-phishing is a likely possibility, Tarakanov said.

The malware has several modules used for different functions that include keylogging, collecting directory listings from the infected computers, searching for and stealing documents in the HWP format that are generated by the South Korean Hancom Office Suite software and allowing attackers to remotely control the infected computers.

The remote control module is actually a modified version of TeamViewer, a legitimate remote control application, Tarakanov said.

The malware reports the infection status and sends all of the stolen data back to the attackers using the same webmail-based technique. The data is encrypted and attached to emails which are sent from the mail.bg accounts to hardcoded Hotmail accounts used by the attackers.

On system startup, the malware disables a firewall product developed by AhnLab, a South Korean security software vendor, if present and then turns off the Windows Security Center service in order to prevent the system from alerting users that no firewall is running.

A lot of South Korean organizations use AhnLab security products and because the targets are almost exclusively from South Korea, the attackers don’t even bother trying to evade security products from other vendors, Tarakanov said.

Taking into account the profiles of the targeted organizations, one could easily suspect that the attackers might be from North Korea, the researcher said. “The targets almost perfectly fall into their sphere of interest.”

One piece of evidence that supports this theory has to do with the geographic location of the Internet Protocol (IP) addresses used by the attackers.

“During our analysis, we observed ten IP addresses used by the Kimsuky operators,” Tarakanov said. “All of them lie in ranges of the Jilin Province Network and Liaoning Province Network, in China.”

“Interestingly, the ISPs providing Internet access in these provinces are also believed to maintain lines into North Korea,” the researcher said, adding that no other IP addresses have been discovered that would put the attackers’ activity in other IP ranges.

South Korea is frequently attributing cyberattacks against organizations and institutions in the country to North Korean hackers. However, with most cyberattacks in general, establishing the location of attackers with a high degree of certainty is not possible.


View the original article here

Tuesday, 30 July 2013

Microsoft to connect schools in South African white-spaces project

Microsoft is expanding the push for so-called "white spaces" broadband to South Africa, where it will help to deploy the technology in a pilot project serving five primary and secondary schools.

The pilot project is aimed at getting schools in rural parts of the country's northeastern Limpopo province connected to the Internet. If successful, it could give South Africa a tool that would help the country reach its goal of affordable broadband for 80 percent of the population by 2020.

White spaces are unused frequencies in TV bands, which Microsoft, Google and others advocate making available on an unlicensed basis for wireless broadband. Advocates won approval for that use in 2008 in the U.S., which was the first country to authorize white spaces. To ensure the new networks use only the slivers of spectrum in between licensed uses, devices need to have a database of licensed users and sensors to detect other activity in the band.

Commercial white-spaces networks are just starting to get off the ground in the U.S., but Microsoft has talked with governments in at least 50 other countries about the possibility of making such frequencies available, said Paul Garnett, Microsoft's director for technology policy.

TV channels are in the same general area of the spectrum band worldwide, so widespread use of white spaces could create a market for mass-produced, low-cost wireless devices, Garnett said. Africa, with more than 1 billion, could play a big role in making that happen, he said.

"That's a huge market, so if there are ways for us to expand access in those markets, then yes, that absolutely helps to create that global marketplace that any new technology is looking for to scale," Garnett said.

Just as the U.S. did, countries across Africa are converting their TV networks from analog to digital, which makes broadcasting more efficient and frees up some of the bandwidth for other uses. But in South Africa, there also are more frequencies in that band that haven't been claimed for anything, he said. That might create an easier path for unlicensed white spaces, which in the U.S. faced strong opposition from TV broadcasters and some other wireless users. South Africa is still evaluating whether to authorize unlicensed white-spaces networks, Garnett said.

"It's an even bigger opportunity ... for this kind of access to radio spectrum than exists in the U.S. or the U.K.," he said. For example, while some U.S. residents suffer from slow DSL (digital subscriber line) speeds, they at least have copper phone lines. Some parts of Africa have no connectivity at all, he said.

In the South African project, Microsoft will work with the University of Limpopo, government agencies and a local network builder called Multisource. The project will set up a central white-spaces radio at the university and one at each of the five schools.

At the schools, the project will give laptops to teachers and make tablets available in a classroom for students. Those clients will talk to special Wi-Fi access points that connect on the back end to the local white-spaces radio. Each school's radio will in turn connect to the Internet through the main white-spaces radio at the university, which has a fiber network.

Though each school's white-spaces radio will have a range of about 10 kilometers, initially they are intended only for use in the schools.

The project will also provide projectors, training and educational content, as well as solar panels where electricity is unavailable or unreliable, Garnett said.

The Limpopo project is part of a broader Microsoft initiative called 4Afrika, which has also included a white-spaces effort in Kenya.

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com


View the original article here