Feeds

Russian space research org targeted by mystery malware attack

Korean message forum becomes cyber-espionage hub

Using blade systems to cut costs and sharpen efficiencies

Security researchers have discovered a targeted attack against Russian hi-tech firm that appears to originate in Korea.

The "Sanny" attack* is malware-based and geared towards stealing login information from Russian telecommunications, information technology and space research organisations. The first stage of the assault features a malicious Russian language MS Word document designed to drop malware onto compromised PCs. This establishes a backdoor on infected machines, establishing a botnet in the process.

The Command and Control channel for this botnet is embedded on a legitimate page, a Korean message board called "nboard.net", according to an analysis of the attack by web security firm FireEye. The malware sends messages to two pre-programmed Yahoo! webmail address, one in Korea, if the board becomes unavailable.

Extracted data is normally sent to a public message board that does not require authentication, so details of victims are visible. Stolen data includes Outlook login credentials as well as username/passwords that Firefox remembers for different online services such as Hotmail, Facebook, etc. Apart from login credentials, the malware also profiles the victims, for example by victim_locale, victim_region, and other relevant information from the Windows REGISTRY of infected computers. This information is then posted to the Korean message board before been extracted and purged over a two day cycle by the unidentified attacker.

Apparent victims include a Russian Space Science research unit at a Russian University and ITAR-TASS, the Russian state-owned news agency.

Although it doesn't have proof, FireEye reckons that a Korean is the most likely perpetrator of the attack.

"Though we don’t have full concrete evidence, we have identified many indicators leading to Korea as a possible origin of attack." FireEye researchers Alex Lanstein and Ali Islam conclude in a jointly authored blog post on the attack.

More technical details can be found in a blog post by FireEye here. ®

* So named by the security researchers for one of the email addresses used by the attackers.

The smart choice: opportunity from uncertainty

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.