Story image

Highly-targeted cyberattacks surround upcoming Winter Olympics

09 Jan 18

Next month’s Winter Olympics have proved to be easy picking for cybercriminals.

McAfee released a report that revealed cybercriminals have targeted organisations that are involved in the fast approaching Winter Olympics held in South Korea.

The ‘hacking campaign’ has run from December 22 and, according to McAfee, has the signs of a ‘nation state adversary that speaks Korean’.

The investigation is ongoing so the attack has yet to be attributed, although the news comes at a delicate time given North Korea has agreed to hold high-level talks with South Korea in an effort to ease hostility between the two nations – it will be the first talks between the nations for two years.

McAfee states targets including ski suppliers and ice hockey teams received an email that claimed to be from South Korea’s national counter-terrorism council. The email contained a document with malicious intent that if opened would open a concealed back channel in their computers that hackers could exploit at a later date.

“Theoretically, if they get into the network hosting the Pyeongchang email network for the Olympics, they have any number of possibilities moving inside. It depends where the networks are connected — to specific teams, committees, planners at a high level,” says McAfee senior analyst, Ryan Sherstobitoff.

Sherstobitoff cautioned that this could only be the beginning as major events attract cybercriminals and hackers.

McAfee said the hackers used a more sophisticated method than the average “spear phishing” attack, installing malicious software without making the victim download a file, which would often be flagged by a security program.

These fileless malware attacks using Microsoft Powershell are becoming an increasingly popular tactic, with the number of attacks more than doubling in the third quarter of last year, McAfee said.

General manager for EMEA at Barracuda Networks, Wieland Alge says increasingly cybercriminals are targeting particular attacks rather than sending it to everyone.

"The malware infected emails targeted at organisations linked to the Winter Olympics fits into the general trend we are observing at the moment where cyber criminals are increasingly relying upon targeted attacks rather than mass attacks,” says Alge.

“Traditionally we have seen mass campaigns that promise something fairly generic – such as lottery winnings or free tickets to an event. However cyber attacks are becoming ever more targeted and sophisticated as spear phishing emails become an increasingly lucrative tool for cyber criminals.”

Hillstone CTO's 2019 security predictions
Hillstone Networks CTO Tim Liu shares what key developments could be expected in the areas of security compliance, cloud, security, AI and IoT.
Can it be trusted? Huawei’s founder speaks out
Ren Zhengfei spoke candidly in a recent media roundtable about security, 5G, his daughter’s detainment, the USA, and the West’s perception of Huawei.
Oracle Java Card update boosts security for IoT devices
"Java Card 3.1 is very significant to the Internet of Things, bringing interoperability, security and flexibility to a fast-growing market currently lacking high-security and flexible edge security solutions."
Sophos hires ex-McAfee SVP Gavin Struther
After 16 years as the APAC senior vice president and president for McAfee, Struthers is now heading the APJ arm of Sophos.
Half of companies unable to detect IoT device breaches
A Gemalto study also shows that the of blockchain technology to help secure IoT data, services and devices has doubled in a year.
Huawei founder publically denies spying allegations
“After all the evidence is made public, we will rely on the justice system.”
Malware downloader on the rise in Check Point’s latest Threat Index
Organisations continue to be targeted by cryptominers, despite an overall drop in value across all cryptocurrencies in 2018.
IoT breaches: Nearly half of businesses still can’t detect them
The Internet of Thing’s (IoT’s) rapid rise to prominence may have compromised its security, if a new report from Gemalto is anything to go by.