https://www.tomshardware.com/tech-industry/cyber-security/south-korean-telecom-company-attacks-torrent-users-with-malware-over-600000-people-report-missing-files-strange-folders-and-disabled-pcs Skip to main content (*) ( ) Open menu Close menu Tom's Hardware [ ] Search Search Tom's Hardware [ ] RSS US Edition flag of US flag of UK UK flag of US US flag of Australia Australia flag of Canada Canada * * Reviews * Best Picks * Raspberry Pi * CPUs * GPUs * News * Coupons * More + Newsletter + PC Components + SSDs + Motherboards + PC Building + Monitors + Laptops + Desktops + Cooling + Cases + RAM + Power Supplies + 3D Printers + Peripherals + Overclocking + About Us Forums Trending * What is an AI PC * Copilot+ PCs * Snapdragon X Elite * Lunar Lake * Ryzen 9000 * Blackwell When you purchase through links on our site, we may earn an affiliate commission. Here's how it works. 1. Tech Industry 2. Cyber Security South Korean telecom company attacks customers with malware -- over 600,000 torrent users report missing files, strange folders, and disabled PCs News By Jowi Morales published 26 June 2024 ISP sends malware to hundreds of thousands of customers to stop them from using a file-sharing service. * * * * * * * Comments (22) KT Corporation logo on building (Image credit: JTBC) Korean news organization JTBC recently discovered through an in-depth investigation that KT Corporation, one of the largest telecom providers in South Korea, deliberately infected over 600,000 users with malware over their use of torrent services. The issue began in May 2020 when Webhard, a Korean cloud service provider, was inundated with user complaints of unexplained errors. The company discovered that its Grid Program, which relies on BitTorrent peer-to-peer file sharing, had been compromised. An anonymous representative of Webhard said, "There is a suspicion of a hacking attack on our grid service. It's very malicious, interfering with it." anonymous interview (Image credit: JTBC) Upon further investigation, the company noted that all affected users had KT as their internet service provider. The representative added, "Only KT users have problems. What the malware does on the user's PC is to create strange folders or make file invisible. It completely disables the Webhard program itself. In some cases, the PC itself was also disabled because of it, so we reported it." Police officials acted on the information and discovered it came from KT's own data center south of Seoul. The authorities say that KT may have violated South Korean laws, including the Protection of Communications Secrets Act and the Information and Communications Network Act. They've since identified and charged 13 individuals, including KT employees and subcontractors directly connected to the malware attack last November, but the investigations continue today. According to the news report, KT said it directly planted the malware on its customers that use Webhard's Grid Service, as it was a malicious program and that "it had no choice but to control it." However, the main problem here wasn't Webhard's use of the BitTorrent protocol but the installation of malware on customer computers without consent. Webhard and KT have fought in the past over the latter's use of its Grid Service. The former says that it's saving tens of billions of Korean Won by allowing its users to use peer-to-peer services to store and transfer data instead of storing it on its servers. On the other hand, the massive number of Grid Service users is straining KT's network, and the two companies went to court to resolve the issue. The judiciary actually ruled in favor of KT. It said that Webhard didn't pay KT network usage fees for its peer-to-peer system and didn't explain to its users how the Grid Service works in detail. Therefore, it wasn't unreasonable for KT to block Webhard's network traffic. Stay On the Cutting Edge: Get the Tom's Hardware Newsletter Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. [ ][ ]Contact me with news and offers from other Future brands[ ]Receive email from us on behalf of our trusted partners or sponsors[Sign me up] By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. South Korean court ruling on Webhard-KT Case (Image credit: JTBC) But instead of blocking IP addresses, KT nuked Grid Service users with malware. Unfortunately, most of them were individuals, not businesses or corporations, and they had no idea what was going on. KT's move to send and install malware on hundreds of thousands of Grid Service users seems like a financial move, as it likely just wanted to stop them from continually using Webhard's BitTorrent file-sharing service. But whatever KT's intentions were, this move led to missing files and damage to customer PCs. Its users were more than just inconvenienced; they likely had to deal with computer problems that stemmed from the company's actions. Jowi Morales Social Links Navigation Freelance News Writer More about cyber security Kaspersky HQ U.S. bans Kaspersky and hands out sanctions to execs -- 100 days until class-leading antivirus ban takes effect Apple Intelbroker claims they hacked Apple in the same week as AMD Latest Hori Steam Controller, Midnight Black Hori announces official Valve-licensed Steam Controller -- launches on Halloween in four colors See more latest > TOPICS Malware See all comments (22) [ ] 22 Comments Comment from the forums * razor512 Were they uploading malware files disguised as various other files, or did they find a way to inject malware into an otherwise safe torrent download? Reply * 35below0 "The judiciary actually ruled in favor of KT. It said that Webhard didn't pay KT network usage fees for its peer-to-peer system and didn't explain to its users how the Grid Service works in detail. Therefore, it wasn't unreasonable for KT to block Webhard's network traffic." Malware is bad for everyone. :/ Retaliating by spreading malware is cartoon villain level of planning and execution. Reply * TheOtherOne When it's the ISP itself, they have probably hundreds of different ways to send malware to their users. It doesn't have to be attached to a TORRENT file. Reply * Sluggotg Gee, there's an ISP I would love to use...... I wonder if people are going to be smart enough to Permanently ditch that ISP and demand Jail Time for Senior Management? How can any business think that is OK to do? Reply * Grobe Sluggotg said: How can any business think that is OK to do? Maybe because battery manufacturers have far greater issues and this "little incident" is getting hidden behind the shadows - my speculation Reply * CmdrShepard ISP sends malware to hundreds of thousands of customers to stop them from using a file-sharing service. How is that even legal? 1. People are paying for your ISP service 2. You don't invest in expanding your network capacity (probably shower shareholders and CxOs with money instead) 3. Instead of sending notices and disabling access if you really can't be arsed to implement proper network congestion management you infect customers with malware?!? Like, they should be out of business yesterday. Closed, sold for scrap, and all executives who approved or knew about this sent straight to jail. Reply * Grobe Ok, I read the article and I'm left with some (maybe non-relevant) questions Does the ISP take this action for all kind of torrent or only those used by a specific service/software ? When searching online for "Webhard's Grid Service" - I only get search results assuming this is in fact a local electric grid, no search results indicates any form for torrent services. What gives? Very different local name that doesn't appear unless using Korean search engines ? Reply * derekullo Moral of the story is to use a sandboxed computer for downloading torrents. Reply * USAFRet derekullo said: Moral of the story is to use a sandboxed computer for downloading torrents. All comes through the same IP address, which is what the ISP knows about and controls. Reply * hotaru251 CmdrShepard said: How is that even legal? different country have different rules over what can be done. That wouldnt fly in states but may not be agaisnt law in korea (idk korean law) Reply * View All 22 Comments Show more comments Most Popular [missing-im]'Believe it' You can use a Raspberry Pi to detect Naruto hand seals with the power of AI [missing-im]Blacklisted Huawei intros first consumer SSDs -- KitStore Xtreme 200 lineup stretches up to 4TB [missing-im]Boot loop delays Microsoft's forced Windows 11 Version 23H2's rollout -- controversial update hits a roadblock [missing-im]Consumer DRAM, VRAM pricing to rise as much as 8% in the coming quarter, TrendForce predicts [missing-im]Intel Core Ultra 7 258V mobile processor matches top Ryzen 'Phoenix' chips in BAPCO performance charts [missing-im]SSD shredder destroys hundreds of SSDs and flash drives per hour, also eats smartphones -- Verity Systems' MediaGone Media Shredder retails for $12,600 [missing-im]Chinese chipmaker samples 128 core server CPU with chiplets -- Infinity Fabric-like interconnect in Loongson's 3E6000 combines four chips into one [missing-im]Micron is the last memory maker to join the EUV party -- company aims for EUV DRAM mass production in 2025 [missing-im]The death of Windows 10 ignites PC market rebound -- market projected to be up 5% this year, 8% in 2025 [missing-im]Frore unveils waterproof AirJet Mini Sport solid-state active cooling device -- fanless cooling solution can now be used underwater [missing-im]Intel launches optical compute interconnect chiplet: Adding 4 Tbps optical connectivity to CPUs or GPUs Tom's Hardware is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site. * Terms and conditions * Contact Future's experts * Privacy policy * Cookies policy * Accessibility Statement * Advertise with us * About us * Coupons * Careers (c) Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036. []