Seoul: Fake tax invoice files embedded with malicious code linked to North Korean hackers have been found circulating online in a security threat targeting South Koreans, according to a Seoul-based cybersecurity company Tuesday. The files, which appear to be legitimate tax documents, are actually a sophisticated ruse designed to infect users' systems with malware.
According to Yonhap News Agency, ESTSecurity has identified the presence of KimJongRAT-infected files circulating on the internet, attributing the malware to the Pyongyang-sponsored hacking group, Kimsuky. The malicious software is cleverly disguised as a PDF document, which in reality contains a shortcut redirecting users to a site where more harmful files are downloaded.
The cybersecurity firm highlighted the targeted nature of the attack, noting that the malicious code was specifically designed to exploit vulnerabilities within South Korean users' systems. "While Microsoft is enhancing security, KimJongRAT remains an extremely effective attack method in environments with weak security features," ESTSecurity stated, emphasizing the importance of keeping software up to date.
Furthermore, ESTSecurity advised users to exercise caution by checking file extensions before executing any files, as a precautionary measure against inadvertently activating malicious code. The ongoing threat underscores the need for heightened cybersecurity awareness and robust protective measures among South Korean internet users.