Malware used to infect visitors to official Afghan government websites


  • TECH
  • Monday, 22 Dec 2014

BEWARE: Malware is being linked to Afghan government websites.

WASHINGTON: Malicious software likely linked to China is being used to infect visitors to a wide range of official Afghan government websites, US cybersecurity researchers say.

ThreatConnect, a Virginia-based cybersecurity firm, said its researchers last week found a corrupted JavaScript file that is being used to host content on gov.af websites, and there are no antivirus protections available for the malware.

Rich Barger, chief intelligence officer of ThreatConnect, told Reuters his company was confident the new campaign, Operation Poisoned Helmand, was linked to the Poisoned Hurricane campaign detected this summer by another security firm, FireEye, that linked it to Chinese intelligence.

He said the latest attack was very recent and one time-stamp associated with the Java file was from Dec 16, the same day Chinese Prime Minister Li Keqiang visited Afghanistan to meet with Afghanistan's chief executive officer, Abdullah Abdullah.

China is seeking to take a more active role in Afghanistan as the United States and NATO reduce their military presence.

"We found continued activity from Chinese specific actors that have used the Afghan government infrastructure as an attack platform," Barger said, noting that Chinese intelligence could use the malware to reach a wide array of global targets checking trusted Afghan government sites for information.

Barger said the attack was a variant of what he called a typical "watering-hole" attack in which the attackers infect a large number of victims, and then follow up with the most "promising" hits to extract data.

He said researchers this summer saw a malicious Java file on the website of the Greek embassy in Beijing while a high-level delegation led by Keqiang was visiting Greek Prime Minister Antonis Samaras in Athens.

The two events were not directly related, Barger said, and additional research was needed into the status of ministerial and official government websites on or around the dates of notable Chinese delegations and or bilateral meetings.

The malware was found on a variety of Afghan government websites, including the ministries of justice, foreign affairs, education, commerce and industry, finance and women's affairs, according to ThreatConnect, which was formerly known as CyberSquared.

The report emerged as the United States sought help from China, Japan, South Korea and Russia in combating cyber attacks such as the one Washington on Friday accused North Korea of carrying out against Sony Pictures. — Reuters

Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

Crypto company Tether invests $200 million in brain-chip maker Blackrock Neurotech
EU to probe Meta over handling of Russian disinformation, FT reports
US man charged with sex-related crimes, used Instagram to lure teens
Apple's iPadOS subject to tough EU tech rules, EU says
TikTok creators fear economic blow of US ban
OpenAI to use FT content for training AI models in latest media tie-up
ChatGPT faces Austria complaint for ‘uncorrectable errors’
Social media platform X back up after outages, Downdetector shows
Sleeping Amazon driver’s fatal crash into teacher was preventable, US lawsuit says
Elon Musk’s China trip pays off with key self-driving hurdles cleared

Others Also Read