This page was machine-translated and may differ from the original. View original
[World Security Expo] Igloo Corporation Shares Cyber Attack Information and Response Strategies

Sharing tips for preventing spearphishing
Intelligence-based defense system is a must
Igloo Corporation presented cyberattack trends and countermeasures, emphasizing the need for integrated automation to respond to new cyberattacks.
Igloo Corporation participated in the 21st World Security Expo held from the 20th to the 22nd, introducing its solutions and giving a presentation on cyber attacks.
As the frequency of unknown malware tools and code usage increases, there is a growing call for linking threat intelligence to respond to sophisticated threats.
Attacks are becoming increasingly diverse, and managing numerous security solutions and analyzing security events with limited budgets and personnel is challenging.
Integrated automation is attracting significant attention because it provides visibility into threats by integrating and automatically linking multiple security solutions.
The presenter said, “As important as having good solutions is having the capabilities to operate them within a security organization,” and added, “We also need systems and expertise to effectively respond to evolving security threats.”
Security incidents continue to occur, including a ransomware attack on the Colonial Pipeline server in May of last year, which caused the 8,850km pipeline facility to shut down.
The perpetrator of this attack is Darkside ransomware, which has access rights. It was an attempt at remote access using brute force password guessing to secure the system, and as major security incidents occurred one after another in the United States, the Biden administration declared an all-out war on cybercrime.
In most attacks, spear phishing has the highest initial penetration rate. Spear phishing is a method of deceiving and infecting users through various means, such as sending official documents from trusted organizations, business cooperation, or seminar materials.
The presenter emphasized four things to remember to prevent spear phishing: △ Be suspicious of unusual character combinations at the end of the reply URL, △ Do not open attached files from any source, △ Do not expose passwords and personal information, and △ Apply the latest security patches to document programs and OS.
In addition to spear phishing, phishing attacks aimed at stealing user accounts are also common. These attacks harvest user accounts by prompting them to enter their account and password through login errors.
Recently, hackers have been targeting operational technology, which offers significant potential for profit. The presenter noted that attackers are constantly researching ways to achieve greater returns at lower costs.
Looking back at the damage to domestic public institutions, attacks exploiting VPN vulnerabilities were carried out by the North Korean hacker group Kimsuky. They targeted internal mail systems and KMS authentication servers, exposing sensitive information. Igloo Corporation said that to prevent such attacks, it will minimize external connections to its operational technology network and use a physical network connection solution that only allows one-way data transmission.
DDoS continues to evolve and is the most dangerous attack, with ransomware-based DDoS cyberattacks on the rise.
Igloo Corporation stated that protection must be provided from the initial service section to the point of contact between the internal and external elements. It is crucial to establish a preemptive defense system to detect external abnormal traffic, analyze internal infections, and prevent widespread attacks. Furthermore, a threat intelligence-based cyberattack defense system must be established.
Meanwhile, Igloo Corporation announced that it will change its name from Igloo Security in March 2022, establish a new corporate identity focused on security and data, and pursue a wide range of new businesses based on its digital capabilities. In line with this, the company is accelerating its business diversification to identify future growth opportunities by consolidating its core competencies in artificial intelligence, big data, and cloud computing with Piolink and Codemind, acquired last year.
Igloo Corporation participated in the 21st World Security Expo held from the 20th to the 22nd, introducing its solutions and giving a presentation on cyber attacks.
As the frequency of unknown malware tools and code usage increases, there is a growing call for linking threat intelligence to respond to sophisticated threats.
Attacks are becoming increasingly diverse, and managing numerous security solutions and analyzing security events with limited budgets and personnel is challenging.
Integrated automation is attracting significant attention because it provides visibility into threats by integrating and automatically linking multiple security solutions.
The presenter said, “As important as having good solutions is having the capabilities to operate them within a security organization,” and added, “We also need systems and expertise to effectively respond to evolving security threats.”
Security incidents continue to occur, including a ransomware attack on the Colonial Pipeline server in May of last year, which caused the 8,850km pipeline facility to shut down.
The perpetrator of this attack is Darkside ransomware, which has access rights. It was an attempt at remote access using brute force password guessing to secure the system, and as major security incidents occurred one after another in the United States, the Biden administration declared an all-out war on cybercrime.
In most attacks, spear phishing has the highest initial penetration rate. Spear phishing is a method of deceiving and infecting users through various means, such as sending official documents from trusted organizations, business cooperation, or seminar materials.
The presenter emphasized four things to remember to prevent spear phishing: △ Be suspicious of unusual character combinations at the end of the reply URL, △ Do not open attached files from any source, △ Do not expose passwords and personal information, and △ Apply the latest security patches to document programs and OS.
In addition to spear phishing, phishing attacks aimed at stealing user accounts are also common. These attacks harvest user accounts by prompting them to enter their account and password through login errors.
Recently, hackers have been targeting operational technology, which offers significant potential for profit. The presenter noted that attackers are constantly researching ways to achieve greater returns at lower costs.
Looking back at the damage to domestic public institutions, attacks exploiting VPN vulnerabilities were carried out by the North Korean hacker group Kimsuky. They targeted internal mail systems and KMS authentication servers, exposing sensitive information. Igloo Corporation said that to prevent such attacks, it will minimize external connections to its operational technology network and use a physical network connection solution that only allows one-way data transmission.
DDoS continues to evolve and is the most dangerous attack, with ransomware-based DDoS cyberattacks on the rise.
Igloo Corporation stated that protection must be provided from the initial service section to the point of contact between the internal and external elements. It is crucial to establish a preemptive defense system to detect external abnormal traffic, analyze internal infections, and prevent widespread attacks. Furthermore, a threat intelligence-based cyberattack defense system must be established.
Meanwhile, Igloo Corporation announced that it will change its name from Igloo Security in March 2022, establish a new corporate identity focused on security and data, and pursue a wide range of new businesses based on its digital capabilities. In line with this, the company is accelerating its business diversification to identify future growth opportunities by consolidating its core competencies in artificial intelligence, big data, and cloud computing with Piolink and Codemind, acquired last year.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















