Feeds

Japanese govt sucked dry for TWO YEARS by Trojan

Nastie may have nicked meeting documents

Providing a secure and efficient Helpdesk

The Japanese government has uncovered an advanced Trojan attack which may have lain undiscovered on its networks leaking confidential data for over two years.

The Finance Ministry told the local Kyodo news service that the first infection came in January 2010, with the most recent taking place in November 2011, after which the attacks apparently stopped.

However, the infections were only discovered last week as part of an on-going security audit of the ministry’s IT systems begun by a contracted firm in May.

So far, 2,000 machines have been checked and a disconcertingly high number – 123 – were found to be infected by Trojan, the report said.

The government is trying to play down the incident by claiming that confidential information such as taxpayers’ details has not been leaked, and that the infected computers belonged mainly to junior staff, although the malware may have accessed documents related to ministry meetings.

The report references hacktivists Anonymous, which last month launched denial of service attacks and web defacements of several government and political sites including the Finance Ministry, although this Trojan attack appears at first sight not quite to fit the MO of the group.

The Trojan was apparently undetected by the anti-virus software installed on the government PCs and lay undetected for a long period of time – hallmarks of a more sophisticated advanced persistent threat-style attack.

The ministry has yet to identify exactly how the PCs became infected and has replaced the hard disks on all affected computers, the report said.

Last October, a Trojan attack on the machines of several Japanese lawmakers was uncovered.

The data-stealing malware arrived as a dodgy attachment and caused hijacked machines to communicate with a server located in China. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.