South Korean Ransomware Victims Searched for Help. The Hacker Was Already Waiting on the Other Side

(Photo=Pixabay)

South Korea has built a global reputation around technology, making the case especially jarring. A business that presented itself as a solution to a cyberattack was, according to a South Korean court, working with the person behind the attack.

The scheme was simple enough to look legitimate from the victim’s side.

A computer was infected with Magniber ransomware, malicious software that encrypts files and makes them unusable unless a victim obtains a decryption key. The victim, confronted with unfamiliar extensions attached to encrypted files, searched online for a way to recover the data.

A data recovery company appeared to have the answer.

What the victim could not see was how the company knew exactly what to advertise.

According to the Seoul Central District Court, the hacker behind the ransomware supplied the company with information about the file extensions that would appear after Magniber infected a computer. The company used those extensions as search advertising keywords on internet portals and posted them on blogs.

In other words, the attacker was helping the company offering the rescue service find the attacker’s own victims.

Once victims contacted the company, its representatives offered to take care of the problem. They said they would pay the hacker, obtain the decryption key and restore the encrypted files.

That turned the data recovery business into something very different from an independent company helping customers after an attack.

The hacker benefited when victims paid Bitcoin to recover their files. The recovery company benefited by collecting fees from people desperate to regain access to their data. Each ransomware infection could create another potential customer.

The arrangement lasted from October 2018 through July 2022. During that period, the company collected about $1.8 million through 730 recovery cases involving Magniber victims, according to the court.

The company’s chief, identified by the surname Park, and an employee surnamed Lee maintained that there was nothing criminal about their role. They argued that victims had voluntarily entered into contracts with the company and that they had simply provided a data recovery service.

The court rejected that explanation.

The key issue was not simply that the company communicated with a hacker to obtain decryption keys. The court found that Park and Lee actively sought information from the hacker that would help them generate more recovery business.

The defendants asked for the extensions that Magniber would attach to infected files because they knew victims were likely to type those extensions into internet searches while looking for help. Those terms could then be purchased as search advertising keywords or placed in blog posts designed to draw victims toward the company.

That relationship, the court found, showed an implicit agreement between the two sides.
The hacker could more easily collect Bitcoin because the recovery company served as a bridge to victims. The company, meanwhile, could earn more recovery fees because the hacker supplied information that helped it reach newly infected users.

The court concluded that the two sides understood what the other was doing and used that activity for their own benefit.

That is what makes the case more troubling than an ordinary ransomware attack. The hacker did not simply lock a computer and wait for payment. The court found a system in which the people apparently offering relief from the crime had incorporated the crime itself into their business.

For victims, nearly every visible part of the transaction could have appeared normal. They searched online for a technical problem, found a company advertising a solution, signed a recovery contract and paid for a service.

Behind that process was a hacker who had already provided the company with information needed to attract them.

The Seoul Central District Court sentenced Park and Lee to three years in prison each for extortion.

In imposing the sentences, the court described the conduct as particularly serious, pointing to the method of the crime, its duration, the number of victims and the amount of money involved. The court also said the defendants continued to deny wrongdoing and showed no remorse.

The numbers leave a striking contrast. The operation continued for nearly four years, involved 730 transactions and brought in about $1.8 million. The two defendants received three year prison terms.

The ruling itself does not establish whether South Korea generally treats cybercrime or financial crime more leniently than other countries, and the facts provided in the case are not enough to make that broader conclusion.

What the case does establish is more unusual.

The victims thought they were paying someone to save them from a ransomware hacker. According to the court, the business collecting their recovery fees was already working with him.

User_logo_rmbg
Jin Lee

Share:

Facebook
Threads
X
Email
Most view
Latest News
Guru's Pick