South Korea’s FSS Identifies 19 Attack IPs Across 12 Countries in Financial Sector Hacking Spree — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


South Korean financial authorities have identified 19 internet protocol (IP) addresses believed to have been used in the recent wave of cyberattacks targeting the country’s financial sector. The IPs were distributed across 12 countries, including the United States, Japan, and Hong Kong, revealing that the attackers routed their intrusions through servers in multiple countries to evade tracking.

According to financial authorities and industry sources on the 6th, the FSS Digital Risk Analysis Team narrowed down 19 attacker IP addresses related to the hacking incidents and distributed them to all financial institutions. The FSS has requested that firms complete self-inspections and remediation of any deficiencies by the 8th.

The identified IPs were located in 12 countries: the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany, and South Korea. U.S.-based IPs accounted for the largest share at five, while Japan, Sweden, and Germany each had two. One domestic South Korean IP was also included.

Evidence of Evasion Tactics

Hackers of unknown nationality appear to have routed their intrusions through IPs of various nationalities to obstruct tracking. The attackers are believed to have probed multiple services within financial firms’ systems, identified vulnerabilities, and then launched concentrated attacks.

One security expert explained, “IP addresses can change continuously, and when a virtual private network (VPN) is used, the same IP can be shared by multiple people. If several IPs launched concentrated attacks on the financial sector at nearly the same time, it would be reasonable to attribute them to the same attacker.”

It is also important to note that IP location alone cannot determine the attacker’s actual location or nationality, given the possibility that attacks were routed through servers or IPs in multiple countries.

Breach Analysis and Inspection Requests

The FSS reportedly narrowed the range of attacker IPs based on addresses that accessed certain banks, including Shinhan Bank, through abnormal pathways and extracted customer personal information.

Financial authorities had previously stated that the attacker IPs used in the breaches of Shinhan, KB Kookmin, Hana, and BNK Busan Bank were identical. The IPs used to attack savings banks and capital companies differed from one another, but the methods themselves are considered similar.

In an official notice, the FSS urged financial firms to “closely identify externally exposed IT assets and services and inspect and remediate vulnerabilities,” and to “verify the authentication, authorization, and validation functions of external-facing systems that could be exploited as intrusion pathways.”

The FSS also distributed a 12-item checklist covering whether the shared attacker IPs have been blocked, whether any intrusion attempts or damage occurred via those IPs, and whether real-time security monitoring systems are operational.

Checklist ItemKey Details
IP BlockingVerify whether shared attacker IPs have been blocked
Intrusion AttemptsCheck for intrusion attempts or damage via attacker IPs
Security MonitoringConfirm real-time monitoring systems for early detection and response to cyber threats
Vulnerability InspectionIdentify externally exposed IT assets and services and remediate vulnerabilities

Note: Summary of key items from the 12-item checklist distributed by the FSS to the entire financial sector.

Financial Firms Expand Self-Inspections

Financial institutions are expanding the scope and timeframe of their inspections to search for additional signs of intrusion. Internet-only bank Toss Bank, for instance, identified abnormal access attempts via some of the attacker IPs flagged by authorities not only in July and August of this year but also as far back as January.

Some in the security industry suspect the attacks originated from China, citing traces of a Chinese-language AI penetration testing tool that was publicly released in July. However, authorities have only shared the nationalities of the attacker IPs and have not specifically mentioned any suspected country of origin for the hacking.

Criminal Investigation and Outlook

The Korean National Police Agency formally converted the financial institution hacking case into a criminal investigation on the same day and established a dedicated investigative team. With the police investigation now added to the inquiries by financial authorities and the Financial Security Institute, observers note that it could take considerable time before the attackers and their methods are concretely identified.

A financial industry source said, “It will take a significant amount of time for the investigations by financial authorities, the Financial Security Institute, and the police to produce results. It would be premature to conclude which country’s hackers are responsible before then.”

This attack is distinguished from previous hacking incidents by the use of AI-powered penetration tools. The financial authorities’ decision to share attacker IPs across the entire financial sector and launch sector-wide inspections is interpreted as a preemptive measure to block additional attacks using similar methods.



Click Here For The Original Source.

——————————————————–

..........

.

.