Showing posts with label Cyber Spies. Show all posts
Showing posts with label Cyber Spies. Show all posts

Friday, 18 September 2015

F-Secure: Espionage Group Working For Russian Government



A group of cyber spies has been working since 2008 for the Russian government and is responsible for various espionage campaigns in which information in the field of foreign policy and security were captured, so claims the Finnish anti-virus firm F-Secure in a comprehensive report (pdf).

The group is called "Duke" and is assured seven years running. To infect targets are mainly used spear phishing emails.The messages contain infected attachments, such as a monkey movie, or links to a website that tries to install malware via a non patches vulnerability. After one vulnerability in Adobe Reader, all the vulnerabilities that the group attacked at the time of the attacks already patched.

Victims were then also can protect themselves by installing security updates timely. The only time there is no spear phishing was used was in the "Onion Duke 'malware. This malware was via a malicious Tor server and torrent files distributed. Once Tor users a program through the Tor network inside was pulled in real-time malware added to the file.

Russia

Attributing attacks to a specific country is very difficult, but in this case, F-Secure says that the espionage group is sponsored by the Russian government. Therefore the virus fighter relies on the motivation and goals of the group. "Based on what we now know about the targets that Duke chose the last seven years, it is consistent to entities with foreign policy and security issues associated," said the Finnish anti-virus company.

The main party that benefits from the work of the cyber spies is the Russian government, according to F-Secure. There are Russian words in the Duke-malware detected and the group is active during office hours in Russia. Further targets include the Eastern European Ministries of Foreign Affairs, Western think tanks and government agencies and even Russian-speaking drug dealers. "All available evidence suggests we believe that the group is working for Russia and we are not aware of evidence that shows otherwise see."

Saturday, 25 July 2015

Cyber ​​Spies Added Linux Support To Allow Malware



A group of cyber spies who is held responsible for attacks on the Belgian government , the White House and a variety of other businesses , government agencies and institutions in Europe and the United States has developed new malware that also features Linux support.

The group is "Duke" and has been active for several years. Recently, a new instance of malware from the group discovered called "Seaduke". It is a Trojan designed to steal information and will be used against a small number of valuable objectives.According to both Symantec and Palo Alto Networks involves highly sophisticated malware.

Linux

Finland's F-Secure analyzed the malware and also saw that the Trojan is written in Python and supports both Windows and Linux. According to the virus fighter Seaduke is the first "cross-platform" malware of the Duke group. The first thing is to use the popular scripting language Python. Earlier malware cyber spies were written in the programming languages ​​C and C ++. In addition, the Python code for both Windows and Linux proves to be developed. "We therefore suspect that the Duke group same Python code Seaduke used to attack Linux users," says researcher Artturi Lehtiö.

Lehtiö leaves in front Security.NL know that there are no attacks against Linux users in the "wild" are found. "But it is safe to assume that they have added Linux support to the use," he notes. The question remains how Linux users would be attacked.The Duke group, for example, used a funny movie monkeys to attack Windows users, which in reality was an exe file. There are PDF documents containing exploits for vulnerabilities in Adobe Reader used to infect computers with malware.

Adding Linux support to malware is not new. Earlier this year it was discovered another group of cyber spies who had done this. The group decided to use social engineering to infect Linux users. Attacked users received a rogue HTML5 plugin offered which turned out to be in reality spyware.

Friday, 15 May 2015

Microsoft TechNet Used To Control Infected Computers


Cyber ​​Spies have Microsoft TechNet used to control infected computers. TechNet is a Microsoft portal where IT professionals can find all kinds of information and documentation for Microsoft products. There is also a forum there for questioning.

A group of cyber spies, according to the American security company FireEye from China operated TechNet used to control infected computers. Forum topics and sections were coded IP addresses hidden. The infected computers used to connect to TechNet and were able to identify the IP address which they then had to connect.

This would make it difficult for network administrators to detect an infection or the actual location to figure out the Command & Control server who opted infected computers. FireEye notes that TechNet itself has not been hacked, but there just was placed on a public information forum. The use of well-known websites such as Twitter , Evernote and Dropbox malware is already longer.

After FireEye Microsoft and the tactics of the attackers had discovered the IP addresses in the forum topics and sections were replaced by IP addresses of American companies. In addition, the board accounts were locked so that cyber spies could not change the custom IP addresses. In this way FireEye and Microsoft could identify the victims of the spying campaign.How many organizations victim of this group were infected and how they were let security know.

Thursday, 23 April 2015

Funny Monkeys Movie Success Cyber Spies



A group of cyber spies before the White House and the US State Department attacked proving very successful in organizations, companies and other targets to penetrate through more than a funny monkey movie. The group is by the Russian anti-virus firm Kaspersky Lab also "Office Monkeys" mentioned, but also get the names and CozyDuke CozyBear.

The attackers were particularly since the second half of 2014 are very active and use different methods of attack, including links to zip files. These zip files contain a self extracting rar file a blank PDF file shows as a distraction. In another successful group of attack were called Flash movies sent as e-mail attachments. A good example is the annex "Office Monkeys LOL Video.zip".

The zip file contains an .exe file that a flash video of a couple of monkeys in an office shows. In the background the exe file to install sophisticated malware. The file might have been widely opened by a victim, as the virus fighter says. Many of the malware that the group used is fake digital certificates from Intel and AMD signed, what should hinder detection. Once activated the malware steals all kinds of information and files systems.

Friday, 6 February 2015

Research: Cyber Spies Sloppy Programmers


Groups that advanced persistent threats (APTS) for cyber espionage prove to be sloppy programmers use, says a researcher ( pdf ) of the British anti-virus firm Sophos . The virus fighter compared the malware cybercriminals applied by cyber spies.

Apts are often considered sophisticated attacks, in which attackers long time to access the network from a target managed to obtain. However, the quality of the malware used appears to be disappointing, says researcher Gabor Szappanos. For example, there appeared to be no quality control in the APT-groups. "A big part of their creations is not well tested, and they do not see why some functionality is not working," he tells.

It also appears that ordinary malware writers have more knowledge than the known exploits APT groups. Something which is bad news, because APT groups focusing on specific targets, while the malware from the malware writers has a much greater range. The APT groups do not have extensive skills when it comes to exploits. New exploits are quickly utilized, but it comes to units which have been developed by others or come from Metasploit.

Usually they develop exploits yourself and in the case of other people's exploits are barely changed. Metasploit is a framework that is offered by security firm Rapid7 and allows security professionals to test the security of systems. According Szappanos let his research shows that when security researchers and administrators respond rapidly to undetected leaks, they probably handle this type of APT groups.

"Despite this, the malware writers mentioned in the report should not be underestimated. They develop sophisticated Trojans and know that spread to major organizations. The fact that they are not good with exploits does not mean that they are less dangerous," concludes the researcher.