logo

Lazarus_Group__2013__Dark_Seoul_Cyberattack.pdf

ID: f8e71ed1-872c-484b-97af-b25d753313e9

STIX ID: report--f8e71ed1-872c-484b-97af-b25d753313e9

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2013-06-28

Last Modified Date: 2013-06-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This paper analyzes the March 20, 2013 "Dark Seoul" attack that disrupted major South Korean banks and broadcasters, outlining a kill-chain from spearphishing and a compromised legitimate website to exploitation of CVE-2012-1889, deployment of backdoors and an infostealer, DNS poisoning to harvest credentials, and the Jokra wiper that overwrote MBRs and disks on thousands of machines; the authors conclude the operation caused high impact at large scale (>48,000 infected) despite being low in technical sophistication compared with known APT campaigns.