Story image

Highly-targeted cyberattacks surround upcoming Winter Olympics

09 Jan 18

Next month’s Winter Olympics have proved to be easy picking for cybercriminals.

McAfee released a report that revealed cybercriminals have targeted organisations that are involved in the fast approaching Winter Olympics held in South Korea.

The ‘hacking campaign’ has run from December 22 and, according to McAfee, has the signs of a ‘nation state adversary that speaks Korean’.

The investigation is ongoing so the attack has yet to be attributed, although the news comes at a delicate time given North Korea has agreed to hold high-level talks with South Korea in an effort to ease hostility between the two nations – it will be the first talks between the nations for two years.

McAfee states targets including ski suppliers and ice hockey teams received an email that claimed to be from South Korea’s national counter-terrorism council. The email contained a document with malicious intent that if opened would open a concealed back channel in their computers that hackers could exploit at a later date.

“Theoretically, if they get into the network hosting the Pyeongchang email network for the Olympics, they have any number of possibilities moving inside. It depends where the networks are connected — to specific teams, committees, planners at a high level,” says McAfee senior analyst, Ryan Sherstobitoff.

Sherstobitoff cautioned that this could only be the beginning as major events attract cybercriminals and hackers.

McAfee said the hackers used a more sophisticated method than the average “spear phishing” attack, installing malicious software without making the victim download a file, which would often be flagged by a security program.

These fileless malware attacks using Microsoft Powershell are becoming an increasingly popular tactic, with the number of attacks more than doubling in the third quarter of last year, McAfee said.

General manager for EMEA at Barracuda Networks, Wieland Alge says increasingly cybercriminals are targeting particular attacks rather than sending it to everyone.

"The malware infected emails targeted at organisations linked to the Winter Olympics fits into the general trend we are observing at the moment where cyber criminals are increasingly relying upon targeted attacks rather than mass attacks,” says Alge.

“Traditionally we have seen mass campaigns that promise something fairly generic – such as lottery winnings or free tickets to an event. However cyber attacks are becoming ever more targeted and sophisticated as spear phishing emails become an increasingly lucrative tool for cyber criminals.”

McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
25% of malicious emails still make it through to recipients
Popular email security programmes may fail to detect as much as 25% of all emails with malicious or dangerous attachments, a study from Mimecast says.
Google Cloud, Palo Alto Networks extend partnership
Google Cloud and Palo Alto Networks have extended their partnership to include more security features and customer support for all major public clouds.
Using blockchain to ensure regulatory compliance
“Data privacy regulations such as the GDPR require you to put better safeguards in place to protect customer data, and to prove you’ve done it."
A10 aims to secure Kubernetes container environments
The solution aims to provide teams deploying microservices applications with an automated way to integrate enterprise-grade security with comprehensive application visibility and analytics.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill.