HomeSecurityThe attack on Sony from a Thai hotel

The attack on Sony from a Thai hotel

Sony

Hackers who leaked sensitive information from Sony Pictures Entertainment  (SPE) computers appear to have used a high-speed Internet connection from a five-star hotel in Bangkok, Thailand, to get the data online, according to a person investigating the incident.

Researchers were able to trace the connection to the St. Regis Hotel, but it is uncertain whether the hackers, acting under the name “Guardians of Peace” (GOP), rented a room, or used the hotel lobby, or even hacked the network from a remote location, as Bloomberg reports.

The leak was revealed earlier this month and concerns documents containing personal data for 47,000 people, including Sony employees, partners and Hollywood stars such as Sylvester Stallone.

As for the identity of the perpetrators, that still remains unknown. However, researchers have taken clues from the analysis of malware (called WIPALL by Trend Micro and Destover by Kaspersky) found on Sony systems, and everything points to North Korea, which has officially denied any involvement in Sunday's attack.

More evidence pointing to Thailand is the initial location of the data leak from an IP address belonging to a university in the country and used in the malware's communication with the GOP.

Aside from the group's name, under which the hackers promoted themselves, there is no information about its members. Security experts have speculated about who might be sponsoring the group's activities and have noted similarities to other attacks carried out by the DarkSeoul, which is believed to be linked to North Korea.

 After analyzing the malware used in the Sony case, they discovered other technical similarities with Shamoon, a group that attacked Aramco, a Saudi Arabian oil company.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS