South Korean police have arrested a CEO and five employees for manufacturing more than 240,000 satellite receivers preloaded or updated to include DDoS, at the request of a buyer.
See also: New DDoS botnet campaign targets IoT devices

Although neither company has been named, the two companies have been working together since 2017. In November 2018, the acquiring company made a specific request to include DDoS functionality, with the South Korean manufacturer agreeing. The functionality needed to counter attacks from a competing entity.
The exact way in which the DDoS functionality on the devices was exploited was not determined, but these attacks are always illegal when targeting external systems. Additionally, users of the satellite receivers were unwittingly participating in attacks and may have experienced reduced performance during these incidents.
From January 2019 to September 2024, the device manufacturer shipped 240,000 satellite receivers, 98,000 of which had a DDoS module pre-installed. The rest received the functionality through a later firmware.

Korean police uncovered the malicious plot after receiving information from Interpol, while the operation also affected a suspect who had been placed on an international wanted list.
The six people arrested in Korea, one of whom was the CEO, are now facing charges related to violations of the law for promoting DDoS functionality, which puts users at risk.
In addition, the court also approved the seizure of the company's assets and the confiscation of 61 billion KRW ($4.35 million), the amount the company is estimated to have earned by selling the malicious satellite receivers.
The operators of the company that purchased the equipment remain at large, and Korean police are seeking international cooperation to locate and arrest them.
See also: Internet Archive: Recovers its functionality after DDoS attacks
A DDoS (Distributed Denial of Service) attack is an attack that aims to disrupt the functionality of a network or website by flooding it with a huge volume of fake requests. During a DDoS attack, thousands of computers infected with malware, also known as “botnets”, coordinate to carry out the attack, thus managing to overload the target’s resources, blocking access to it by legitimate users. DDoS attacks can cause severe service disruption and financial damage and losses for website owners. To deal with DDoS attacks, it is necessary to implement enhanced security measures and use specialized detection and response solutions.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
