Feeds

JUST LIKE US: Hackers who work for gov seem almost... ORGANISED

Malware quartermasters dish out exploits on demand, say researchers

High performance access to file storage

State-sponsored hackers are looking less like traditional hacking crews and more like military units as they share infrastructure and adopt strict hierarchies, according to new research.

Infosec firm FireEye has identified links between 11 APT campaigns, including use of the same malware tools, shared code, binaries with the same timestamps, and signed binaries with the same digital certificates.

The 11 APT campaigns targeted a wide swath of industries and appeared unrelated at first, until cyber-sleuths uncovered digital evidence linking the attacks.

The shared development and logistics operation used to support several APT actors in distinct but overlapping campaigns points to the role of a "digital quartermaster". The role of this cyber organiser is different from that occupied by exploit brokers (firms and/or individuals who discovered or re-sell security vulnerabilities and exploits), according to FireEye.

"The main difference between the quartermaster that we identified and exploit-brokers is that we have no evidence to show the quartermaster also develops exploits for known or unknown vulnerabilities," Ned Moran, a senior malware researcher from FireEye, told El Reg. "We know that the quartermaster develops custom remote access tools but we do not know if they also develop and supply operators with exploits."

The emergence of a common development and logistics centre means that attackers are adopting an industrialised approach to cyber-spying, something that defenders of trade secrets and other digital assets are facing more organised and capable adversaries.

The mission of the digital quartermaster is to supply and maintain malware tools and weapons to support cyber espionage. The digital quartermaster also might be a cyber arms dealer, a common supplier of tools used to conduct attacks and establish footholds in targeted systems. However, common features in the campaigns tied together by FireEye suggest it's more likely we're dealing with someone who works exclusively with Chinese hacking groups, rather than the hi-tech equivalent of an arms dealer prepared to supply all and sundry.

"Based on the Chinese language user interface of the 9002 Builder, the tool used to build the 9002 remote access Trojans, we believe the digital quartermaster spoke or read Chinese," Moran told El Reg. "It is also possible that the operators of the 11 different campaigns also spoke or read Chinese."

FireEye's report revealing the emergence of malware cyber arms dealer, entitled Supply Chain Analysis: From Quartermaster to Sunshop, can be found here (PDF). The main findings of the study are summarised in a blog post here. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.