Trojan update fingered for massive South Korean breach
Software company ESTsoft was responsible for a massive compromise of some 35 million South Koreans last month after it pushed out malware to some of the country’s largest web companies.
Unidentified hackers uploaded malware to an EFTsoft server through a common, vulnerable DLL module that the company used to send updates to its 25 million subscribers.
The malware and was subsequently uploaded to websites owned by SK Communications, including social networking site Cyworld. South Korea’s National Police Agency pinned the breach on the software provider, which operates popular anti-virus product AIYak. An advisory issued by ESTsoft said hackers had uploaded a backdoor trojan dubbed SOGU, rated as highly dangerous by Trend Micro.