The Curious Case of Encoded VB Scripts : APT.NineBlog
We came across a rather peculiar TTP (Tools, Techniques, and Procedures) in a targeted attack we found recently. This targeted attack uses simpler techniques but still remains effective in infiltrating...
View ArticleSurvival of the Fittest: New York Times Attackers Evolve Quickly
The attackers behind the breach of the New York Times’ computer network late last year appear to be mounting fresh assaults that leverage new and improved versions of malware. The new campaigns mark...
View ArticleOperation Molerats: Middle East Cyber Attacks Using Poison Ivy
Don’t be too hasty to link every Poison Ivy-based cyber attack to China. The popular remote access tool (RAT), which we recently detailed on this blog, is being used in a broad campaign of attacks...
View ArticleNjw0rm – Brother From the Same Mother
FireEye Labs has discovered an intriguing new sibling of the njRAT remote access tool (RAT) that one-ups its older “brother” with a couple of diabolically clever features. Created by the same author as...
View ArticleEvasive Tactics: Taidoor
The Taidoor malware has been used in many ongoing cyber espionage campaigns. Its victims include government agencies, corporate entities, and think tanks, especially those with interests in Taiwan. [1]...
View ArticleOperation DeputyDog: Zero-Day (CVE-2013-3893) Attack Against Japanese Targets
FireEye has discovered a campaign leveraging the recently announced zero-day CVE-2013-3893. This campaign, which we have labeled ‘Operation DeputyDog’, began as early as August 19, 2013 and appears to...
View ArticleHand Me Downs: Exploit and Infrastructure Reuse Among APT Campaigns
Since we first reported on Operation DeputyDog, at least three other Advanced Persistent Threat (APT) campaigns known as Web2Crew, Taidoor, and th3bug have made use of the same exploit to deliver their...
View ArticleEvasive Tactics: Terminator RAT
FireEye Labs has been tracking a variety of advanced persistent threat (APT) actors that have been slightly changing their tools, techniques, and procedures (TTPs) in order to evade network defenses....
View ArticleExploit Proliferation: Additional Threat Groups Acquire CVE-2013-3906
Last week, we blogged about a zero-day vulnerability (CVE-2013-3906) that was being used by at least two different threat groups. Although it was the same exploit, the two groups deployed it...
View ArticleOperation Ke3chang: Targeted Attacks Against Ministries of Foreign Affairs
This week, FireEye released a report detailing how Chinese-speaking advanced persistent threat (APT) actors systematically attacked European ministries of foreign affairs (MFAs). Within 24 hours, the...
View ArticleTrends in Targeted Attacks: 2013
FireEye has been busy over the last year. We have tracked malware-based espionage campaigns and published research papers on numerous advanced threat actors. We chopped through Poison Ivy, documented a...
View ArticleWhere have all the credit cards gone? The cybercrime underground and its ties...
Security researchers have tracked Target’s massive data breach to an individual believed to be operating from Ukraine. The stolen credit card data is already being sold on underground Russian-language...
View ArticleXtremeRAT: Nuisance or Threat?
Rather than building custom malware, many threat actors behind targeted attacks use publicly or commercially available remote access Trojans (RATs). This pre-built malware has all the functionality...
View ArticleFrom Windows to Droids: An Insight in to Multi-vector Attack Mechanisms in RATs
FireEye recently observed a targeted attack on a U.S.-based financial institution via a spear-phishing email. The payload used in this campaign is a tool called WinSpy, which is sold by the author as a...
View ArticleCrimeware or APT? Malware’s “Fifty Shades of Grey”
Some cybercriminals build massive botnets to use unsuspecting endpoints for spam, distributed denial-of-service (DDoS) attacks, or large-scale click fraud. With the aid of banking Trojans, other...
View ArticleOperation Saffron Rose
There is evolution and development underway within Iranian-based hacker groups that coincides with Iran’s efforts at controlling political dissent and expanding offensive cyber capabilities. The...
View ArticleBrutPOS: RDP Bruteforcing Botnet Targeting POS Systems
There have been an increasing number of headlines about breaches at retailers in which attackers have made off with credit card data after compromising point-of-sale (POS) terminals. However, what is...
View ArticleSpy of the Tiger
A recent report documents a group of attackers known as “PittyTiger” that appears to have been active since at least 2011; however, they may have been operating as far back as 2008. We have been...
View ArticleData Theft in Aisle 9: A FireEye Look at Threats to Retailers
While cybercriminals continue to target the payment card and banking information of individual users, they seem increasingly aware that compromising retailers is more lucrative. Targeting retailers is...
View Article