Indian Defense Companies are the current target of cybercriminals

Trend Micro Researchers were alerted to the discovery of a campaign of targeted attacks that have successfully compromised defense industry companies in India, USA, Japan, Israel. Eight victims of this attack have been identified.

The attackers sent out emails with a malicious .PDF attachment, detected by Trend Micro as TROJ_PIDIEF.EED which exploits vulnerability in specific versions of Adobe Flash and Reader (CVE_2011-0611) to drop malicious files on the target’s computer. This malicious payload, detected by Trend Micro as BKDR_ZAPCHAST.QZ, connects to a C&C server and communicates some pieces of information about itself and awaits further commands.

The second stage of the attacks involves two components. The attackers issue commands that instruct the compromised computer to report back networking information and file names within specified directories. Certain targets are instructed to download custom DLLS, detected by Trend Micro as BKDR_HUPIG.B, that contain specific functionality related to the compromised entity.

Once inside the network, the attackers issue commands that cause the compromised computer to download tools that allow them to move laterally throughout the network including those that enable “pass-the-hash” techniques. They then issue additional commands that cause the compromised computer to download a remote access Trojan (RAT) that allows the attackers to take real-time control of the compromised system. Trend Micro detects this RAT as BKDR_HUPIGON.ZXS and BKDR_HUPIGON.ZUY.

Remote Access Trojan

The RAT is called “MFC Hunter” and has three components:

Server – installed on the victims machine and connects to the “hub”

Hub – installed on an intermediary machine and serves as a proxy connection between victim and attacker

MFC – the RAT client that the attackers use to control the victim’s compromised computer

By staging the attacks this way, the attackers maintain two separate methods of control. The first allows them to schedule commands to be run by the compromised computer when it connects to the command and control server. The second allows attackers to take real-time control of the compromised computer using the RAT.

ITVoir NewsDesk


Tags: Trend Micro Researchers, RAT client , Trend Micro detects RAT, Trend Micro trojan

  


Similar Articles
Indian Defense Companies are the current target of cybercriminals
Trend Micro Researchers were alerted to the discovery of a campaign of targeted attacks that have successfully compromised defense industry companies in India, USA, Japan, Israel. Eight victims of thi
Buffalo announces Network Admin Tools for NAS
Buffalo Technology, a global leader in the design, development and manufacturing of wired and wireless networking, network and direct attached storage solutions, announced the availability of Buffalo
Stellar launches Certified Disk Sanitization Services
Stellar a leader in data recovery products and services has launched its all new Disk Sanitization Services along with its well known range of Data Recovery Products.On the launch, Stellar Data Recove
QNAP releases V3.3.2 Firmware with Mac OS X Lion
QNAP Systems, Inc. today released a new version of its NAS Management Software, embedded as firmware, in support of a few popular discontinued models. The new V3.3.2 firmware update adds support for t
Stellar Mac Series of Optimization tool now Lion compatible
Stellar Phoenix a renowned name in data recovery and optimization solutions, announced it’s Mac Series of system optimization tool under Brand Stellar and Stellar Phoenix Data Recovery tools tha
NVIDIA helps transform the PC with Windows 8 Developer Program
NVIDIA announced its Windows 8 Developer Program to provide developers with tools and resources for building applications for the hundreds of millions of ARM and x86-based devices that will take advan
SafeNet Authentication and Hardware Security Modules achieve Compliance Certification from IdenTrust
SafeNet, Inc., a global leader in information security, announced that its eToken PRO, eToken PRO Anywhere, and eToken NG-FLASH Anywhere certificate-based authentication token devices, as well as its
QNAP announces new v3.5 NAS Management Software
QNAP Systems, Inc.announced new V3.5 NAS management software for its Turbo NAS series, embedded as firmware.  The new V3.5 firmware provides compatibility with Apple’s new Mac OS X Lion ope
Stellar Phoenix launches robust tool to repair corrupt PDF files
Stellar Data Recovery an illustrious name in recovery products and services today launched Stellar Phoenix PDF Recovery v1 a robust tool to repair corrupt portable document format files. The convenien
Fortinet threat landscape research reveals new Android Botnet
Fortinet − a leading network security provider and the worldwide leader of unified threat management (UTM) solutions − today released its latest Threat Landscape report, which details a ne
Kaspersky Lab releases latest versions of Kaspersky Internet Security and Kaspersky Anti-Virus
Kaspersky Lab, a leading developer of secure content and threat management solutions, unveiled the 2012 versions of its home user products. The new versions of Kaspersky Anti-Virus and Kaspersky Inter
Stellar Phoenix rolls out advance Mail Recovery tool for 'Thunderbird', 'The Bat'
Stellar Data Recovery a pioneer in data recovery software and services  announced the release of Stellar Phoenix Mail Recovery v1.0 to restore back corrupt, inaccessible and deleted emails. Stell
Pitney Bowes unveils India's first Integrated Document Printing solution
Pitney Bowes India, leading provider of integrated mail and document management systems, services and solutions introduces country’s first complete In-House Mailstream solution with a printer an
Stellar unveils world's first FileMaker database repair utility for MAC
Stellar Data Recovery a leading name in recovery products and services launched world’s First FileMaker database repair utility Stellar Phoenix FileMaker Recovery v1.0. The new Phoenix file make
BMC Software delivers Unified Application Performance Management Solution
BMC Software unveiled the industry’s most robust application performance management (APM) product portfolio. The newly-integrated offering creates a simplified solution for the management of ent
Stellar Launches Advanced Photo Recovery Software to bring back lost memories
Stellar a reckoned name in data recovery software and services announced the release of Stellar Phoenix Photo Recovery v 4.0 to recover back lost photo, audio and video files from camera cards, mobile
Naaptol unveils Anroid-based application for Smart phone users
Naaptol, a leading virtual home shopping brand has come up with an android-based application to reach out to the smart phone users. This new platform will be enabling Android smart phone users to make
Make your smartphone smarter with Kaspersky Mobile Security Solutions 9
To enrich a smartphone with full proof security Kaspersky Lab, a leading manufacturer of secure content and threat management solutions, launched Kaspersky Mobile Security Solutions – targeting
BIOSTAR enhances digital entertainment with BIO-Remote and BIO-Remote2
Now, a remote control for your PC! BIOSTAR MICROTECH launched “BIO-Remote1” control device and the “BIO-Remote2” software suite, enabling users to remote-control their PC in th
Secure your data with Blue Coat Comprehensive Web Security Solution
Web security is the vital issue of concern these days. Keeping in mind,  Blue Coat Systems, Inc., a leading provider of Web security and WAN optimization solutions, introduced the Blue Coat Proxy

 
 



 


 
Mr. M A Mannan shares his views, "Corsair still has a long..

Mr. M A Mannan

Country Manager , Corsair Memory India

Mr. M A Mannan shares his views, "Cors..

 

Mr Sunil Chandna

CEO

Stellar Data Recovery
 



 

Is Indian IT on the road to beat recessionary impacts?

  • Yes
    [79.49%]
  • No
    [16.67%]
  • Can't say
    [3.85%]