Showing posts with label Duke Malware. Show all posts
Showing posts with label Duke Malware. Show all posts

Friday, 18 September 2015

F-Secure: Espionage Group Working For Russian Government



A group of cyber spies has been working since 2008 for the Russian government and is responsible for various espionage campaigns in which information in the field of foreign policy and security were captured, so claims the Finnish anti-virus firm F-Secure in a comprehensive report (pdf).

The group is called "Duke" and is assured seven years running. To infect targets are mainly used spear phishing emails.The messages contain infected attachments, such as a monkey movie, or links to a website that tries to install malware via a non patches vulnerability. After one vulnerability in Adobe Reader, all the vulnerabilities that the group attacked at the time of the attacks already patched.

Victims were then also can protect themselves by installing security updates timely. The only time there is no spear phishing was used was in the "Onion Duke 'malware. This malware was via a malicious Tor server and torrent files distributed. Once Tor users a program through the Tor network inside was pulled in real-time malware added to the file.

Russia

Attributing attacks to a specific country is very difficult, but in this case, F-Secure says that the espionage group is sponsored by the Russian government. Therefore the virus fighter relies on the motivation and goals of the group. "Based on what we now know about the targets that Duke chose the last seven years, it is consistent to entities with foreign policy and security issues associated," said the Finnish anti-virus company.

The main party that benefits from the work of the cyber spies is the Russian government, according to F-Secure. There are Russian words in the Duke-malware detected and the group is active during office hours in Russia. Further targets include the Eastern European Ministries of Foreign Affairs, Western think tanks and government agencies and even Russian-speaking drug dealers. "All available evidence suggests we believe that the group is working for Russia and we are not aware of evidence that shows otherwise see."

Saturday, 25 July 2015

Cyber ​​Spies Added Linux Support To Allow Malware



A group of cyber spies who is held responsible for attacks on the Belgian government , the White House and a variety of other businesses , government agencies and institutions in Europe and the United States has developed new malware that also features Linux support.

The group is "Duke" and has been active for several years. Recently, a new instance of malware from the group discovered called "Seaduke". It is a Trojan designed to steal information and will be used against a small number of valuable objectives.According to both Symantec and Palo Alto Networks involves highly sophisticated malware.

Linux

Finland's F-Secure analyzed the malware and also saw that the Trojan is written in Python and supports both Windows and Linux. According to the virus fighter Seaduke is the first "cross-platform" malware of the Duke group. The first thing is to use the popular scripting language Python. Earlier malware cyber spies were written in the programming languages ​​C and C ++. In addition, the Python code for both Windows and Linux proves to be developed. "We therefore suspect that the Duke group same Python code Seaduke used to attack Linux users," says researcher Artturi Lehtiö.

Lehtiö leaves in front Security.NL know that there are no attacks against Linux users in the "wild" are found. "But it is safe to assume that they have added Linux support to the use," he notes. The question remains how Linux users would be attacked.The Duke group, for example, used a funny movie monkeys to attack Windows users, which in reality was an exe file. There are PDF documents containing exploits for vulnerabilities in Adobe Reader used to infect computers with malware.

Adding Linux support to malware is not new. Earlier this year it was discovered another group of cyber spies who had done this. The group decided to use social engineering to infect Linux users. Attacked users received a rogue HTML5 plugin offered which turned out to be in reality spyware.