Story image

Rumours fly about who was behind the PyeongChang Olympics hack

16 Feb 18

As speculation grows about who was behind the attacks on the PyeongChang Olympic Games opening ceremony, Talos Researchers identified a malware called “Olympic Destroyer” that may have been behind the attacks.

Recorded Future believes that the Olympic Destroyer malware should be treated as serious because of its destructive nature and ability to spread laterally.

It uses in-built Windows tools Psexec and WMI to infect systems and render data useless. It also use password stealing tool Mimikatz to extract credentials and continue moving across a target network.

The PyeongChang attack also included a set of Active Directory credentials and a software key, which suggests the malware had previously been used in an early reconnaissance phase.

In December, an attack on a telecommunications provider was the beginning stages of the attack on the Games.

“All samples of the Olympic Destroyer malware variant targeting the IT provider were timestamped five minutes prior to the compilation of the samples identified by Talos researchers as targeting the PyeongChang 2018 network. This suggests a parallel, two-pronged attempt to target the Olympics event, aimed at both organizers and infrastructure providers,” a report from US threat intelligence firm Recorded Future says.

The team also suggests that there are disparate code overlaps in the malware, suggesting a ‘false flag’ operation that is throwing researchers off the trail and diluting evidence.

Recorded Future has taken the analysis one step further, although there’s still no firm evidence as to who conducted the attack.

Recorded future director of strategic threat development Priscilla Moriuchi says that finding out who is behind the attacks is important because it shapes responses from government, victims and the public.

“Accurate attribution is both more crucial and more difficult to determine than ever because adversaries are constantly evolving new techniques and the expertise required to identify a sophisticated actor keeps increasing.”

The report suggests that the malware could originate from North Korea, China or Russia – but the case is not straightforward.

 “Complex malware operations make us take pause to reevaluate research methods and make sure the research community is not being misled by its own eagerness to attribute attacks,”explains Recorded Future principal security research of Inskit Group, Juan Andres Guerrero Saade.

Researchers from Intezer spotted code similarities between Olympic Destroyer and threat actors in China, including the APT3, APT10 and APT12 groups.

Recorded Future’s research group found code similarities linked with malware families belonging to the Lazarus Group in North Korea.

“The Olympic Destroyer campaign comes at a precarious time of geopolitical tensions with several possible perpetrators but conclusive proof in any one particular direction has not yet been shared,” Saade concludes.

Read further coverage of the PyeongChang Olympic hacks:

Winter Olympics hacked: Was it just disruptive or something more sinister?

Surprise - the PyeongChang Winter Olympic Games were hacked 

What MSPs can learn from Datto’s Channel Ransomware Report
While there have been less high profile attacks making the headlines, the frequency of attacks is, in fact, increasing.
Cisco expands security capabilities of SD­-WAN portfolio
Until now, SD-­WAN solutions have forced IT to choose between application experience or security.
AlgoSec delivers native security management for Azure Firewall
AlgoSec’s new solution will allow a central management capability for Azure Firewall, Microsoft's new cloud-native firewall-as-a-service.
How to configure your firewall for maximum effectiveness
ManageEngine offers some firewall best practices that can help security admins handle the conundrum of speed vs security.
Exclusive: Why Australian enterprises are prime targets for malware attacks
"Only 14% of Australian organisations are continuously training employees to spot cyber attacks."
Exclusive: Why botnets will swarm IoT devices
“What if these nodes were able to make autonomous decisions with minimal supervision, use their collective intelligence to solve problems?”
Bitdefender announces security integration with Kaseya
The new partnership will allow VSA by Kaseya’s cloud and on-premises users to deploy and manage security with Bitdefender Cloud Security for MSPs.
Why you should leverage a next-gen firewall platform
Through full lifecycle-based threat detection and prevention, organisations are able to manage the entire threat lifecycle without adding additional solutions.