Feeds

Oil and gas giants' PCs polluted by new cyber-spy Trojan

Advanced Persistent Threat 'Mirage' group is back

3 Big data security analytics techniques

Hackers bent on espionage have infiltrated a large oil company in the Philippines, an energy biz in Canada and a military organisation in Taiwan among others, claim researchers.

The crooks also targeted other as yet unidentified businesses in Brazil, Israel, Egypt and Nigeria, according to the preliminary results of a probe by Dell SecureWorks. The researchers have been tracking the hackers' so-called Mirage campaign for about five months since April.

Secureworks reckons the group behind these latest attempts to obtain company secrets are the same miscreants who launched attacks against a Vietnamese petroleum firm and others in February in the so-called Sin Digoo affair. Email addresses linked to command servers associated with the Mirage campaign also emerged in the Sin Digoo op.

"This indicates that either the actors behind both the Sin Digoo Affair and Mirage APT [Advanced Persistent Threat] campaigns are the same person, or they are working within the same hacker group," the Dell SecureWorks team concluded in a report.

One of the people behind the Sin Digoo campaign previously ran a blackhat search engine optimisation business, which uses shady techniques to boost clients' websites up search rankings. And the malware used to infect corporate machines in the Mirage espionage disguises its connections to the hackers' server as harmless Google search queries. It pulls off this trick by crafting HTTP requests that look like typical lookup requests to Google's search engine frontend. Targeted emails containing booby-trapped attachments are used to push inject the Mirage Trojan onto Microsoft Windows PCs.

Victims are simply tricked into executing the files, at which point the malicious software installs itself and phones home with the specifications of the infected computer. It is not immediately clear exactly what kind of data is stolen by the spying software. Some variants of the worm include a line from The Matrix: "Neo, welcome to the desert of the real." Another variant includes a lyric from the REM song It's the end of the world as we know it.

The IP addresses of the systems used by hackers to remotely control Mirage-infected machines belong to the China Beijing Province Network (AS4808), as did three of the IP addresses used in the Sin Digoo campaign. "AS4808 is known for many other connections to malware and is considered by some to be a hotbed of espionage C2s [command and control servers]," SecureWorks concludes.

More details on the espionage campaign can be found on the SecureWorks website. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.