Suspected state hacking campaign used commercial software


  • TECH
  • Monday, 29 Dec 2014

MISUSE: There were cyber attacks that relied on software sold to companies that wanted to test its own defences.

SAN FRANCISCO: A previously undisclosed hacking campaign against military targets in Israel and Europe is probably backed by a country that misused security-testing software to cover its tracks and enhance its capability, researchers said.

The attack program relied on software usually sold by Boston-based Core Security to companies and other customers that want to test their own defences, said researchers coordinated by Israel's independent Computer Emergency Response Team, or CERT.

The researchers from CrowdStrike and start-up Cymmetria will present their unusual findings at the annual Chaos Communication Congress security conference in Hamburg.

Criminal hackers have made use of penetration-testing tools such as Metasploit for years, other experts said, but most major government-sponsored hacks have specially written tools supplemented by free and widely available programs. That is in part because commercial programs could be traced back to specific customers.

Over time, however, the exposure of campaigns relying on the same tailor-made tools have made it easier for investigators to attribute those attacks to a specific government.

Using the Core Security program, which typically costs US$10,000 (RM35,000) or US$20,000 (RM70,000), could help muddy the waters, and CrowdStrike analyst Tillmann Werner said it could also help a second-tier cyber-power skip some of the work frequently undertaken by China, Russia and the United States.

"The most likely answer is they didn't have the capability to do it on their own," Werner said of the hackers, adding that "there is no risk of leaving tool-marks."

Werner and Cymmetria Chief Executive Gadi Evron, who also chairs the Israeli CERT, said they did not know who was behind the campaign.

But Evron said that one suspect would be Iran, judging by the victims and other evidence. The researchers dubbed the new campaign Rocket Kitten, following CrowdStrike's convention for naming all suspected Iranian hacking groups as Kittens.

Iran has beefed up its Internet operations in the years since its nuclear program was attacked by Stuxnet, an unusually destructive virus developed by the United States and Israel.

Evron said the team had uncovered seven connected attacks so far since April, including attempts to steal information from an Israeli company "adjacent to the defence and aerospace industry," an Israeli academic institution, a German-speaking defence agency, and an Eastern European defence ministry. At least the Israeli attempts failed, he said.

The attacks typically began with carefully targeted e-mails with Excel spreadsheet attachments sent to top executives. The recipients were prompted to allow a type of miniature program known as macros to run inside the Microsoft Corp spreadsheets, and if they agreed, malicious software would install. That software would download part of Core's Core Impact tool, the researchers said.

Core's licensing terms forbid use of its program against unsuspecting third parties, and Core Vice President of Engineering Flavio de Cristofaro said the company had not heard of such misuse in at least five years.

De Cristofaro said the company would assist the CERT if asked and in any case would try to track down how the software was pried away from the watermarks and other technical restrictions designed to limit its spread.

"We will follow that down," de Cristofaro said.— Reuters

Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

Walmart-backed fintech One launches 'buy now, pay later' loans, CNBC reports
Coca-Cola signs $1.1 billion deal to use Microsoft cloud, AI services
Google invests $640 million in new data centre in Netherlands
NatWest CEO sees 'material opportunities' in AI
Trump poised to clinch $1.3 billion social media company stock award
Amazon launches low-cost grocery delivery subscription plan in US
Spotify profits up, but lower marketing hits user growth
Adobe to bring full AI image generation to Photoshop this year
Tesla shares edge higher ahead of quarterly results
TikTok risks fines as EU issues ultimatum over app launch

Others Also Read