Showing posts with label Syrian Attack. Show all posts
Showing posts with label Syrian Attack. Show all posts

Tuesday, 9 June 2015

US Military Gets Website Temporarily Offline After Attack



The US military has its own website temporarily taken off the air after it was hacked. The Syrian Electronic Army (SEA) claimed the attack. The group employs a statement that it could carry out the attack on the content delivery network (CDN) to target the website.

In the control unit the attackers discovered that it was possible to adjust the secure content trails. So it was possible to add content to the website of the Army. As proof of the SEA posted several screenshots of the control panel. According to the US military, the attackers knew indeed a part of army.mil to compromise. To prevent further damage or theft of military data, it was decided to temporarily take down the site, so late Brigadier Malcolm Frost know . Meanwhile, the website is back online.

Tuesday, 3 February 2015

Skype Malware Steals Battle Plan Syrian Opposition

The Syrian opposition has become the target of attackers who managed to steal confidential documents nearly 8GB via Skype malware, including battle plans, troop locations, names of fighters and lists of deceased soldiers, as well as all sorts of other data. The attackers would logs more than 31,000 Skype calls have stolen and had provided the Skype databases. These databases contain the contacts of the victim and call details.In this way, the attackers were a comprehensive picture of the relationships within the opposition.

To obtain the information the attackers made several Skype accounts with female profile pictures. The profiles were then used against male members of the Syrian opposition. First, a relationship with the targets are built before they were sent via Skype malware. In addition, the attackers asked regularly whether the targets were using Skype on their phone or computer.Probably to determine what needed to be used for malware.

Before the malware was sent the attackers targeted first asked for a photo. Then they sent supposedly a picture of the "woman" behind the profile back. It was a self-extracting RAR archive with a .pif file extension. If the victim opened the so-called photo got to see a picture, while in the background the Dark Comet Remote Access Tool (RAT) was installed. Through this malware, the attackers had full control over the computer.

According to security firm FireEye that the attack campaign discovered the attackers used the stolen Skype databases to select next victims. In addition, would share many opposition members forced computers. Once a computer was infected, the attackers of several people could steal their data. "This information probably fulfilled an important role in the operational plans and tactical decisions of the enemy, but were possible at the expense of human lives," said FireEye.