South Korean telco deliberately infected thousands of users with malware

A cybersecurity icon projecting from a laptop screen.
(Image credit: Shutterstock / song_about_summer)

One of the largest telecommunications providers in South Korea allegedly targeted hundreds of thousands of its own customers with malware in a bid to stop them using torrenting sites.

Local media outlets claim Korea Telecom (KT) used illegal methods to try and curb the use of peer-to-peer (P2P) downloading software.

Apparently, KT set up an entire division dedicated to developing, maintaining, and distributing the malware. The entire operation started in May 2020 and, at one point, affected roughly 600,000 people.

Police involved

The victims were the users of the Grid Program, which suddenly started creating strange folders, or outright hiding downloaded files - and in some cases, the infected PCs just stopped working altogether. 

A Grid Program representative told the media that only the people using KT’s internet lines were affected, TechNadu said.

Since the malware seemingly came from KT’s data center, the Bundang IDC center, the police were soon involved. Apparently, the Gyeonggi Southern District Office suspects KT violated the Communications Secrets Protection Act (CSPA) and the Information and Communications Network Act (ICNA). In the meantime, the KT CEO stepped down as well. 

In total 13 individuals were identified and referred for prosecution, it was said. A new investigation started last month, as well.

P2P sites can often burden networks, in a similar way legitimate streaming services do, too. At one point, South Korean telecommunications providers were even fighting a legal battle with Netflix over who should pay for the network operation and construction costs.

That being said, it would not be in the domain of sci-fi if KT opted for a different method of trying to prevent widespread P2P use. Obviously, such a thing would warrant at least a lawsuit, and given that people’s sensitive files could be involved too, it could end up hurting KT a lot.

Via The Register

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
malware
Google warns of legit VPN apps being used to infect devices with malware
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Microsoft reveals over a million PCs hit by malvertising campaign
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
A display showing off the Google TV homepage, with icons for 1917, Scoob!, YouTube and Twitch (among others)
This dangerous malware botnet now covers 1.6 million Android TVs - find out if you're at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring