Proprietary · · 24 days

SimDisk auto-update delivered DDoS malware

Attackers abused SimDisk's auto-update path during the June 2013 South Korea attacks. The update installed malware used for DDoS and remote control.

SimDisk was a South Korean cloud-storage and file-sharing client with an auto-update feature. During the 2013 South Korea attack wave, researchers linked malware delivery to an update installer retrieved from the SimDisk website.

The distribution method made the attack efficient. Users did not need to visit a phishing site or install a new product; the trusted client update channel supplied the malicious component. That placed SimDisk alongside other Korean software-update abuse in the DarkSeoul period.

Public reporting tied the malware to DDoS activity against South Korean government and media targets around the anniversary of the Korean War. The same threat cluster is commonly associated with destructive and disruptive operations against South Korean banks, broadcasters, and government sites.

The record is kept narrow. It tracks the SimDisk update channel and the DDoS/backdoor payload path, not every DarkSeoul operation or every wiper used in 2013.

Notes

  • Two of this record's four references have effectively stopped supporting it, which is why the story above is vaguer than the reporting. The Avast post now 404s with no Internet Archive capture at any timestamp.
  • The local copy in refs/ was taken on 2026-08-13 and did return 200, but the manifest records it as 282 characters of visible text and no article, so it never carried the detail either. The Symantec post redirects to community.broadcom.com.
  • The two malware names this record cites, Trojan.Castov and TROJ_DIDKR.A, come from the surviving secondary reporting rather than from either of those references.

Appendix · Affected releases

SimDisk_setup.exe simdisk updater
  • No digest for the trojanized installer appears in any retained source, searched 2026-09-02. What the reporting gives are names, recorded above as indicators: SimDisk.exe, Symantec's Trojan.Castov and Trend Micro's TROJ_DIDKR.A.
  • MalwareBazaar holds nothing under either signature, which is unsurprising for a 2013 Korean campaign given the repository only began collecting in 2020.

References

  1. SimDisk malware attackblog.avast.com
  2. Four years of DarkSeoul cyberattacks against South Korea continue on anniversary of Korean Warsymantec.com
  3. South Korean cyberattacks mark anniversary of DarkSeoulzdnet.com
  4. Last-minute paper: Reveal the facts behind the DDoS attackvirusbulletin.com

Source record: proprietary/simdisk/meta.yaml