Defense companies persistently targeted by cyber spies
Posted on 01.02.2012
Bookmark and Share
Researchers from security companies Zscaler and Seculert have issued a warning about bogus emails targeting employees of defense-related organizations around the world in order to trick them into installing malware.

"Dear Sir, It is a conference that you may possibly be interested in. More information is attached below," says in the recent emails. The attached file is a specially crafted PDF that, at first glance, looks like a completely harmless invitation to a relevant industry conference such as the IEEE Aerospace Conference or an Iraq Peace Conference.


But, once downloaded and opened, the file exploits vulnerabilities within Adobe Reader in order to drop and run a Trojan that opens a backdoor into the system.

"The malware dropped and launched from the PDF exploit has been seen to be virtual machine (VM) aware in order to prevent analysis within a sandbox," explain the researchers. "The Trojan functionality is decrypted at run-time, and includes expected functionality, such as, downloading, uploading, and executing files driven by commands from the C&C."

"Communication with the C&C is over HTTP but is encoded to evade detection. The Trojan file name (e.g., 'msupdate.exe') and the HTTP paths used in the C&C (e.g., '/microsoftupdate/getupdate/default.aspx') are used to stay under the radar by appearing to be related to Microsoft Windows Update."

According to the researchers' report, these attacks has been going on since 2009 and are thought to be executed by the same cyber criminal group. The aforementioned example is only the latest incarnation of their approach, and is probably not going to be the last.

The general purpose of the dropped malware is to exfiltrate important information from the companies' systems, and given the targets, it's not far-fetched to assume that a nation-station is likely to be behind these attacks.






Spotlight

17% of the world's PCs are unprotected

Posted on 30 May 2012.  |  In a study that analyzed data from voluntary scans from an average of 27-28 million computers per month, McAfee researchers found 17% of the world is browsing the internet completely unprotected.

Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Wed, May 30th
    COPYRIGHT 1998-2012 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //