Case2

Investigation of personal information leakage due to malware infection

Case Background/OverviewCase Background/Overview

Background of the discovery:
A company's PCs were found to be infected with malware. Since there was suspicion that personal information had been leaked, FRONTEO was asked to investigate.

We were asked to identify the infection route and trace the traces of information leakage from the identified infected terminal. Since the source of infection was unknown, the number of terminals to be investigated was several hundred.

Investigation method

- Several hundred surveyed terminals were analyzed using analysis tools in cooperation with a research partner company to visualize the attack route and identify the affected terminals.

- In addition, we investigated less than 30 cyber black markets to see if the leaked information was traded on the dark web.

results

We were able to identify the PC on which the information leak was occurring and even identified that the information had been leaked to the Dark Web.

Dark Web: A major marketplace where illegal goods are traded, a major forum for cyber criminals, and a major search service related to the black market.

case2_darkweb.jpg