HomeLatest NewsCyber SecurityNorth Korean group behind Adobe Flash Zero-Day vulnerability: FireEye

North Korean group behind Adobe Flash Zero-Day vulnerability: FireEye

FireEye said that North Korean group seems to behind Adobe Flash zero-day vulnerability

Preferred Source of Google

Cybersecurity firm FireEye said that North Korean group seems to behind Adobe Flash zero-day vulnerability which was highlighted by KISA (KrCERT) on January 31 and confirmed by Adobe on February 1. Unlike most other industry sources on this, FireEye is linking this Zero-day to . “We assess that the actors employing this latest Flash zero-day are a suspected North Korean group we track as TEMP.Reaper,” said firm.

“We believe the actors behind this latest Flash zero-day are a North Korean group we track as Reaper. We have high confidence that Reaper is a North Korean group as we have seen them mistakenly upload data to command and control server from North Korean IP space. The majority of their targeting has been South Korea focused, targeting the , military, and defense industrial base as well as other industry. They have also taken an interest in predictable North Korean interests such as unification efforts and defectors,” said John Hultquist, Director of Intelligence Analysis, FireEye.

“This is one of the North Korean actors we have been concerned about with respect to the Olympics. They could be leveraged to gather information and possibly carry out attack. We have connected attacks to other North Korean actors, but we have not seen this actor engage in disruptive or destructive activity. Though we have not seen them execute it, we have seen these actors deploy wiper malware,” he added.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →

On Jan. 31, KISA (KrCERT) published an advisory about an Adobe Flash zero-day vulnerability being exploited in the wild. On Feb. 1, Adobe issued an advisory confirming the vulnerability exists in Adobe Flash Player 28.0.0.137 and earlier versions, and that successful exploitation could potentially allow an attacker to take control of the affected system.

FireEye wrote in a blog that they have observed TEMP.Reaper operators directly interacting with their command and control infrastructure from IP addresses assigned to the STAR-KP network in Pyozngyang. The STAR-KP network is operated as a joint venture between the North Korean Government’s Post and Telecommunications Corporation and -based Loxley Pacific. Historically, the majority of their targeting has been focused on the South Korean government, military, and defense industrial base; however, they have expanded to other international targets in the last year. They have taken interest in subject matter of direct importance to the Democratic People’s Republic of Korea (DPRK) such as Korean unification efforts and North Korean defectors.

FireEye said that analysis of the exploit chain is ongoing, but available information points to the Flash zero-day being distributed in a malicious document or spreadsheet with an embedded SWF file. Upon opening and successful exploitation, a decryption key for an encrypted embedded payload would be downloaded from compromised third party websites hosted in South Korea. Preliminary analysis indicates that the vulnerability was likely used to distribute the previously observed DOGCALL malware to South Korean victims.

Advertisement

Adobe stated that it plans to release a fix for this issue the week of Feb. 5, 2018. Until then, we recommended that customers use extreme caution, especially when visiting South Korean sites, and avoid opening suspicious documents, especially Excel spreadsheets. Due to the publication of the vulnerability prior to patch availability, it is likely that additional criminal and nation state groups will attempt to exploit the vulnerability in the near term.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

M Kalam
M Kalam
M Kalam covers technology and e-goverance for TechObserver.in.
Advertisement
- Advertisement -
- Advertisement -

Data centre infrastructure management market to grow sevenfold to $27.4 billion by 2035

The global data centre infrastructure management market will grow from $3.7 billion in 2025 to $27.4 billion by 2035, driven by hyperscale expansion and AI workload demands, according to Global Market Insights Inc.

RELATED ARTICLES