Hack threat to Tibetan activists used as lure

No holds barred discussion on the Buddhadharma. Argue about rebirth, karma, commentarial interpretations etc. Be nice to each other.

Hack threat to Tibetan activists used as lure

Postby PadmaVonSamba » Thu Mar 22, 2012 12:42 am

http://www.computerworld.com/s/article/ ... are_attack
Report about hack threat to Tibetan activists used as lure in malware attack
Hackers trick Tibetan activists into visiting exploit pages by baiting them with a legitimate report from AlienVault
By Lucian Constantin
March 21, 2012 11:20 AM ET
1 Comment

IDG News Service - Hackers are using a recent report about cyberthreats to Tibetan activists as a lure in a new attack against pro-Tibet organizations that distributes Windows and Mac malware, researchers from security vendor AlienVault said Monday.

On March 13, AlienVault published a report about email-based cyberattacks against Tibetan activist organizations including the Central Tibet Administration and the International Campaign for Tibet.

The rogue emails seen in those attacks distributed a booby-trapped Word document that exploited a Microsoft Office vulnerability (designated CVE-2010-3333) to install a variant of Gh0st RAT, a remote access computer Trojan.

AlienVault researchers believe that the Tibet attack campaign was organized by the same group of Chinese hackers that launched the so-called Nitro attacks against dozens of chemical sector companies last year.

However, it seems that even though the cyberespionage operation was exposed, hackers haven't given up on targeting pro-Tibet organizations. In fact, they started using AlienVault's report about the campaign as a lure in new attacks against Tibetan activists, said AlienVault researcher Jaime Blasco in a blog post on Monday.

Newly intercepted rogue emails that use spoofed headers to appear as originating from AlienVault warn recipients that Tibetan activist organizations have been targeted in recent cyberattacks.

The emails contain a "more information" link that leads visitors to a Web page displaying a copy of AlienVault's March 13 report. However, hidden JavaScript code present on the page launches exploits a known Java vulnerability (CVE-2011-3544) in the background, Blasco said.

Successful exploitation attempts result in computer backdoors being installed on both Windows and Mac OS X systems. The Mac backdoor had a zero detection rate on VirusTotal when scanned by AlienVault on Monday, Blasco said. Now, it is detected by six out of the 43 antivirus engines used by the service.

The Mac piece of malware connects to a command and control server hosted on a domain name that was associated in the past with attacks involving the Protux backdoor, Blasco said.

It's not clear whether the Nitro gang is responsible for the new attacks against Tibetan activists, but the group is known to have used similar techniques before. In December 2011, Symantec reported a series of malicious emails sent by the Nitro gang that used the company's original report about the group's operations as a lure.
Profile Picture: "The Foaming Monk"
The Chinese characters are Fo (buddha) and Ming (bright). The image is of a student of Buddhism, who, imagining himself to be a monk, and not understanding the true meaning of the words takes the sound of the words literally. Likewise, People on web forums sometime seem to be foaming at the mouth.
Original painting by P.Volker /used by permission.
User avatar
PadmaVonSamba
 
Posts: 2800
Joined: Sat May 14, 2011 1:41 am

Re: Hack threat to Tibetan activists used as lure

Postby kirtu » Thu Mar 22, 2012 5:20 pm

PadmaVonSamba wrote:The rogue emails seen in those attacks distributed a booby-trapped Word document that exploited a Microsoft Office vulnerability (designated CVE-2010-3333) to install a variant of Gh0st RAT, a remote access computer Trojan.


This is a MS Office vulnerability so get rid of MS Office and replace it with Open Office or Libre Office (after verifying that OO/LO are themselves not vulnerable). Second, remove Windows and replace it with a European proven office version of Linux (pioneered by the city governments of Munich and some Spanish cities) - although this merely reduces rather than eliminates vulnerability. No TGIE office or Tibetan activist group should be using Windows period - doing so just screams "hack me" to the PRC and their partisans (some of whom are not reportedly under PRC control btw). Also enforcing web/internet security is essential - no Word doc downloads for a start, no browsing unknown/untrusted websites, etc.

Kirt
Kirt's Tibetan Translation Notes

“All beings are Buddhas, but obscured by incidental stains. When those have been removed, there is Buddhahood.”
Hevajra Tantra
kirtu
Former staff member
 
Posts: 4129
Joined: Mon Jan 18, 2010 5:29 pm
Location: Baltimore, MD


Return to Open Dharma

Who is online

Users browsing this forum: Google [Bot], MSN [Bot] and 10 guests

>