Showing posts with label Remote Access Trojan. Show all posts
Showing posts with label Remote Access Trojan. Show all posts

Monday, 29 June 2015

FBI Warns Of Malicious Hackers US Government


The FBI has a bulletin distributed among companies that warn of malware that attackers have used to break up the network of a US government agency and, where possible, the sensitive data of tens of millions of civil servants were stolen.

It's about the burglary at the Office of Personnel Management (OPM), where attackers managed to steal twice data. At the first break of the personal data of 4.2 million former and current officials were stolen. The second burglary has a much greater impact. There did attackers to gain access to the system where information on screenings and background checks are stored. It involves highly sensitive data, such as mental health problems, drug and alcohol use, arrests by police and bankruptcies. Also, persons in completing the screening form names fill acquaintances and contacts, as well as the social security number.

This week it was announced that 32 million of potential officials this highly sensitive private data are captured, reports the Washington Times . The attackers made ​​via stolen credentials of an outside company to gain access to the system. The company is responsible for background checks of officials who should be given a "security clearance", said OPM Director Katherine Archuleta this week at a hearing of a Senate committee to know, according to USA Today .

Sakula

In early June the FBI circulated a information bulletin ( pdf ), which warned of the Sakula Remote Access Tool (RAT), reports Public Intelligence . Through the tool attackers had stolen personal identifying information. The warning was published a day after the OPM had the first break on the network warned . Last week left sources told Reuters that the OPM hackers a "special tool" called Sakula were used to control the computers of the administration remotely, making the link between the FBI warning and OPM burglary could be laid. The malware was already at the intrusion on the network of US health insurer Anthem are used. Since the data of 80 million were former and current customers stolen.

In addition to the technical characteristics of the malware also gives the FBI the information bulletin several tips to businesses what they should do after detecting Sakula and what measures can be taken to secure systems preventive heavier. This involves things like the use of reduced duties, limiting local accounts, network segregation, logging and monitoring admin accounts, deploy whitelisting and using the Microsoft Enhanced Mitigation Experience Toolkit ( EMET ). Via this free software from Microsoft it more difficult for attackers to use both known and unknown vulnerabilities.

Friday, 19 June 2015

PowerPoint Leak Used To Spread Malware


Vulnerability in PowerPoint, which was patched by Microsoft last year is now being actively used to infect activists in Tibet and Hong Kong with malware. The attacks are part of a larger campaign that is taking place for years. Remarkably, however, the use of PowerPoint leak.

Previously used the attackers vulnerabilities in Microsoft Office respectively in 2010 and 2012. The use of the PowerPoint leak would for the first time in two years the trend. For the dissemination of the PowerPoint files as well as e-mail attachments using links to Google Drive. To warn activists against the risk of email attachments campaign "was Detach from Attachments "starts. It is just recommended to use cloud storage for sharing files, such as Google Drive.


The fact that the attackers now use Google Drive, according to the investigators as possibly an indication that the attackers adapt accordingly. When users open the PowerPoint updates from Microsoft are not installed and the presentation they can with a remote access Trojan (RAT) become infected. The malware would be recognized by a few virus scanners.

In total, the researchers saw the Canadian CitizenLab five campaigns where the PowerPoint leak was deployed. To let users do not suspect they get to see a real presentation, while the malware is installed in the background. "The recycled content, low detection scanners and that users do not know that these files are malicious, ensure that these attacks are worrying," the researchers said.

Wednesday, 28 January 2015

Kaspersky: NSA Involved Regin Malware


The US National Security Agency is involved or responsible for the advanced Regin-malware , according to the Russian anti-virus firm Kaspersky Lab. The virus fighter relies on an analysis of the virus code and files that were leaked by whistleblower Edward Snowden.

The German newspaper Der Spiegel published the documents ( pdf ) and files on 17 January this year. Under the leaked files also contained a keylogger codenamed QWERTY that would be developed by the NSA. Researchers analyzed this keylogger and discovered that the code is identical to a plug-in of the Regin malware. The researchers noted that the QWERTY keylogger can not be used as a separate module, but is dependent on functionality that is provided by a Regin module.

"Given the extreme complexity of the Regin platform and the small chance that it can be imitated by someone who has no access to the source code, we conclude that the developers of the QWERTY malware and Regin developers are the same or collaborate" says research director Costin Raiu. Previously suggested the Dutch security firm Fox-IT that the malware was created by the NSA or British secret service GCHQ.

Regin, according to Symantec's already in use since 2008, while Kaspersky Lab even a compilation date of 1999 saw over.Include Belgacom and an employee of the German Chancellor Angela Merkel would be attacked by the malware. The espionage malware used a variety of techniques to avoid detection. So it is still unknown how Regin infects computers."Regin stands alone. It is certainly more complex than Stuxnet and Flame when it comes to the design of the platform, functionality and flexibility," Raiu had previously know.

QWERTY 20123.sys:
0ed11a73694999bc45d18b4189f41ac2 (Virustotal Link)

Regin 50251 plugins:
c0de81512a08bdf2ec18cb93b43bdc2d
e9a43ea2882ac63b7bc036d954c79aa1