Malware that pretends to be an update for old versions of Adobe Flash Player, a malware dropper type , has been found on the website of North Korea 's state news agency , KCNA
A security researcher analyzed the source code of the Korean Central News Agency (KCNA) website, and discovered a suspicious file in the root directory, “kcna.user.exploit.exploit.kcmsf”, which contained JavaScript code responsible for downloading an executable file for Flash Player 10.
Another security researcher who writes for InfoSecOtter, put the executable file on VirusTotal's machines, where most of the software (42 out of 55) flagged it as malicious and attributed it the characteristic of a malware dropper, that is, that it downloads and installs malware on the system it is on.
ArsTechnica did its own research and concluded that the fake Flash update was created in December 2012, which corresponds to most of the website's code .
They also found a JavaScript whose function was to check the versions of Flash supported by visitors' browsers. It seems that its purpose was to control the WebTV clients of the website.
An interesting fact discovered by ArsTechnica is that the malware dropper file is present in the code of all pages, and is also easily accessible, but they did not find any string that calls the location of the file.
At this time, there are no details about the malware dropper's exact operation or the address it communicates with, but InfoSecOtter promised to provide more information about the execution code, what modifications it made to the page, and if they manage to find it, the location the specific script communicates with.

