Tucked inside a piece of Windows malware used in the attacks is a component that erases Linux machines, an analysis from Symantec has found. The malware, which it called Jokra, is unusual, Symantec said.
Jokra also checks computers running Windows XP and 7 for a program called mRemote, which is a remote access tool that can used to manage devices on different platforms, Symantec said.
Of course the details are not actually described in much detail. It does sound like I'd have to be running a Windows computer that has mRemote installed, then mRemote would connect to some remote Linux box and, do what exactly? Prompt the Windows user for a login on the Linux box with root privileges? I never run servers that use sudo, so the Windows user would to explicitly log in as root with root's password.
The article doesn't say anything about how these credentials would be obtained. Perhaps it also includes a keylogger? I doubt any of this would work on any network where the Linux administrator had even an inkling of security knowledge. If that's the standard for IT in South Korean banks, the banks deserve whatever problems they may have.
Since the basic malware, "DarkSeoul," has been in the wild for over a year, the fact that it successfully infected banks would be a major worry to me if it were a depositor. Who's in charge of security at these banks?