« There just aren't eno… | Home | It's amazing, the stu… »

Targetted attacks.

Wednesday 25 April 2007 at 3:05 pm
It seems that The Bad Guys (for some value of Bad Guys) are now carefully choosing their targets, and are also carefully choosing personnel who work at those targets and are e-mailing trojan horses, in the form of MS Office documents to those people in the hope that they'll open the bad files and run the exploits. The nature of the payload isn't clear in the article - it sounds like the trojans open connections to systems that the attackers control, and the attackers tunnel back through into the target networks. The scary thing is that the targets include various federal agencies, defense contactors, and (it is said) a couple of nuclear power research facilities... moreover, the attacks are coming from overseas (no surprise, really), usually China or Taiwan. The attacks come at a rate of a couple per site per week - these guys are persistent, I'll give them that.

While this isn't a 0-day technique (the theory's been around for years), this is the first time that it's been recorded as happening as part of a planned, deliberate attack against a major site. Usually you hear about it being part of a last-ditch attack against a small company, sometimes in the guise of what might be considered industrial espionage.

Used tags: , , , , ,
AddThis Social Bookmark Button
Fight Spam! Click Here!

Trackback link:

Please enable javascript to generate a trackback url

three comments recorded.

Well… that’s interesting.

Hasufin - 25 04 07 - 15:13 - Reply to comment?

Mitnick (in his black hat days) would target specific employees in hitting a company. He’d go into the lobby and grab the company’s newsletter and read the section on new hires. Welcome Steve Jensen, our new tech support analyst! He’d then call up the newbie and social engineer a login out of him.

JB (URL) - 27 04 07 - 07:42 - Reply to comment?

That’s more of a social engineering attack… he didn’t write customised trojan horses to attack the network through those people, just his innate glibness.

The Doctor (URL) - 27 04 07 - 10:56 - Reply to comment?


  
Remember personal info?

/ Textile
  (Register your username / Log in)

Notify:
Hide email:

Small print: All html tags except <b> and <i> will be removed from your comment. You can make links by just typing the url or mail-address.