Feeds

Oil and gas giants' PCs polluted by new cyber-spy Trojan

Advanced Persistent Threat 'Mirage' group is back

Choosing a cloud hosting partner with confidence

Hackers bent on espionage have infiltrated a large oil company in the Philippines, an energy biz in Canada and a military organisation in Taiwan among others, claim researchers.

The crooks also targeted other as yet unidentified businesses in Brazil, Israel, Egypt and Nigeria, according to the preliminary results of a probe by Dell SecureWorks. The researchers have been tracking the hackers' so-called Mirage campaign for about five months since April.

Secureworks reckons the group behind these latest attempts to obtain company secrets are the same miscreants who launched attacks against a Vietnamese petroleum firm and others in February in the so-called Sin Digoo affair. Email addresses linked to command servers associated with the Mirage campaign also emerged in the Sin Digoo op.

"This indicates that either the actors behind both the Sin Digoo Affair and Mirage APT [Advanced Persistent Threat] campaigns are the same person, or they are working within the same hacker group," the Dell SecureWorks team concluded in a report.

One of the people behind the Sin Digoo campaign previously ran a blackhat search engine optimisation business, which uses shady techniques to boost clients' websites up search rankings. And the malware used to infect corporate machines in the Mirage espionage disguises its connections to the hackers' server as harmless Google search queries. It pulls off this trick by crafting HTTP requests that look like typical lookup requests to Google's search engine frontend. Targeted emails containing booby-trapped attachments are used to push inject the Mirage Trojan onto Microsoft Windows PCs.

Victims are simply tricked into executing the files, at which point the malicious software installs itself and phones home with the specifications of the infected computer. It is not immediately clear exactly what kind of data is stolen by the spying software. Some variants of the worm include a line from The Matrix: "Neo, welcome to the desert of the real." Another variant includes a lyric from the REM song It's the end of the world as we know it.

The IP addresses of the systems used by hackers to remotely control Mirage-infected machines belong to the China Beijing Province Network (AS4808), as did three of the IP addresses used in the Sin Digoo campaign. "AS4808 is known for many other connections to malware and is considered by some to be a hotbed of espionage C2s [command and control servers]," SecureWorks concludes.

More details on the espionage campaign can be found on the SecureWorks website. ®

Beginner's guide to SSL certificates

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
US government fines Intel's Wind River over crypto exports
New emphasis on encryption as a weapon?
To Russia With Love: Snowden's pole-dancer girlfriend is living with him in Moscow
While the NSA is tapping your PC, he's tapping ... nevermind
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Slap for SnapChat web app in SNAP mishap: '200,000' snaps sapped
This is what happens if you hand your username and password to a 3rd-party
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.