Breaking News

ENDORFY introduces Atlas Electric desks Sony Unveils LinkBuds Clip Open Earbuds be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router Transcend Launches RDE3 microSD Express Card Reader for Next-Generation High-Speed Performance

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Hackers Circulate Malicious Mandiant Report

Hackers Circulate Malicious Mandiant Report

Enterprise & IT Feb 22,2013 0

Symantec has discovered that someone has been performing targeted attacks by using a recent report by a security firm that accuses the Chinese military of supporting widespread cyber attacks on U.S. companies. The report (APT1: Exposing One of China's Cyber Espionage Units) released last week by cyber forensics firm Mandiant, is used as bait in an attempt to infect those who might be interested in reading it, Symantec says.

The report has drawn worldwide attention by both the security world and the general public. This interest is due to the conclusion the report has drawn regarding the origin of targeted attacks, using advanced persistent threats (APT), performed by a certain group of attackers dubbed the 'Comment Crew. '

The email Symantec has come across is in Japanese, but this does not mean there are no emails in other languages spreading in the wild. The email purports to be from someone in the media recommending the report. The attachment is made to appear like the actual report with the use of a PDF file and the name of the company as the file name. However, like in many targeted attacks, the email is sent from a free email account and the content of the email uses subpar language.

Symantec detects the fake report as Trojan.Pidief. Once it's opened, a blank PDF is shown but in the background exploit code for Adobe Acrobat and Reader Remote Code Execution Vulnerability (CVE-2013-0641) is executed. The PDF file may drop Trojan.Swaylib and Trojan.Dropper, which drops Downloader, if the vulnerbility is successfully exploited.

Symantec has also also confirmed that there are multiple variants of the malicious fake report.

Similar tactics have been used in the past, one of which actually involved Symantec. Back in 2011, when the security firm released a whitepaper on another group performing targeted attacks, the attackers took the opportunity to use the publication to infect those interested in reading the paper.

The original report is available from Mandiant at intelreport.mandiant.com/ and charges that a secretive Chinese military unit is behind a series of hacking attacks. Last week it prompted a denial from Beijing and accusations that China was in fact the victim of U.S. hacking.

Tags: Hacking
Previous Post
Intel 3D Graphics Solution Certified for Mobile
Next Post
Seagate Joins The Openstack Foundation And Open Compute Project

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

  • Indonesia's Tokopedia Inverstigates Alleged Data Leak of 91 Million Users

Latest News

ENDORFY introduces Atlas Electric desks
Gadgets

ENDORFY introduces Atlas Electric desks

Sony Unveils LinkBuds Clip Open Earbuds
Consumer Electronics

Sony Unveils LinkBuds Clip Open Earbuds

be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym
Gaming

be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym

ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router
Enterprise & IT

ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router

Transcend Launches RDE3 microSD Express Card Reader for Next-Generation High-Speed Performance
Cameras

Transcend Launches RDE3 microSD Express Card Reader for Next-Generation High-Speed Performance

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed