Members
  • Total Members: 12815
  • Latest: regjoe
Stats
  • Total Posts: 28521
  • Total Topics: 8240
  • Online Today: 924
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: "CosmicDuke" trojan attacks on Western governments!  (Read 630 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
"CosmicDuke" trojan attacks on Western governments!
« on: 05. July 2014., 07:33:46 »


Security researchers have uncovered a link between a Trojan and a recently discovered cyber-espionage tool which suggests cyber-spies behind recent attacks on Western governments cut their teeth writing conventional Trojans.

CosmicDuke combines elements from the Cosmu Trojan and a backdoor known as MiniDuke, previously associated with cyberespionage-style attacks.

MiniDuke, first identified in February 2013, cropped up in attacks against NATO and European government agencies.

Recent analysis by Finnish anti-virus firm F-Secure revealed that the long-running Cosmu strain of information stealers was using the same loader as MiniDuke stage three. Compilation timestamps show it was Cosmu - not MiniDuke - which originally used the common shared loader.

"Moreover, we found that the loader was updated at some point, and both malware families took the updated loader into use," a blog post by F-Secure security researcher Timo Hirvonen explains. "Since Cosmu is the first malware known to share code with MiniDuke, we decided to name the samples showing this amalgamation of the MiniDuke-derived loader and Cosmu-derived payload as CosmicDuke": http://www.f-secure.com/weblog/archives/00002723.html

CosmicDuke infections start by tricking targets into opening either a PDF file which contains an exploit or a Windows executable whose filename is manipulated to make it look like a document or image file. Some of the samples display a decoy document to the user, such as "Ukraine-Gas-Pipelines-Security-Report-March-2014.pdf" in the example cited by F-Secure. Another decoy document poses as a Russian-language receipt for a payment.

Once successfully deployed, CosmicDuke starts collecting information from compromised systems. Its information stealing components include a keylogger, clipboard stealer, screenshot capture, and password-stealers for a variety of popular chat, email and web-browsing programs. CosmicDuke also collects information about the files on compromised systems as well as bundling the capability to export cryptographic certificates and the associated private keys.

Sensitive data hoovered up from compromised systems is uploaded to remote servers via FTP. As well as stealing information, CosmicDuke created a backdoor on compromised networks, allowing miscreants to download secondary malware.

More details on the malware can be found in a more comprehensive technical analysis by F-Secure here (PDF): http://www.f-secure.com/static/doc/labs_global/Whitepapers/cosmicduke_whitepaper.pdf

(ElReg)

Samker's Computer Forum - SCforum.info

"CosmicDuke" trojan attacks on Western governments!
« on: 05. July 2014., 07:33:46 »




 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising