Jump to content

Hackers attack Middle East experts of US thinktanks


Recommended Posts

http://cdn.mos.techradar.com/art/features/mac-virus/main-470-75.jpg

A nebulous group nicknamed "DEEP PANDA" by security researchers is said to be behind a targeted hack of Middle East-based employees of US think tanks.

According to a Crowdstrike blog post, the attacks happened as the situation in Iraq and the Middle East took a turn for the worse. It highlights June 18 as the date the individual attacks started as ISIS attacked the Balji Oil refinery.

The company's co-founder and CTO, Dmitri Alperovitch, claims that DEEP PANDA has ties with the Chinese government (calling it a nation-state cyber intrusion group) and that the shift of direction is a clear indication that China is keen to know what other parties involved in the region are likely to do.

Crowdstrike says that DEEP PANDA uses powershell scripts to fool any traditional security application that may reside on the victim's computer.

They then inject the MadHatter .NET Remote Access Tool, a RAT that runs from the system's memory and doesn't need to be initalled on the system's drive.

According to Alperovitch, DEEP PANDA "presents a very serious threat not just to think tanks, but also multinational financial institutions, law firms, defense contractors, and government agencies" and that the renewed interest on cash-strapped, well-connected not-for-profit organisations can only be a worrying sign.

http://rss.feedsportal.com/c/669/f/415085/s/3c48c127/sc/1/mf.gif


http://da.feedsportal.com/r/199107812598/u/49/f/415085/c/669/s/3c48c127/sc/1/rc/1/rc.img
http://da.feedsportal.com/r/199107812598/u/49/f/415085/c/669/s/3c48c127/sc/1/rc/2/rc.img
http://da.feedsportal.com/r/199107812598/u/49/f/415085/c/669/s/3c48c127/sc/1/rc/3/rc.img

http://da.feedsportal.com/r/199107812598/u/49/f/415085/c/669/s/3c48c127/sc/1/a2.imghttp://pi.feedsportal.com/r/199107812598/u/49/f/415085/c/669/s/3c48c127/sc/1/a2t.imghttp://feeds.feedburner.com/~r/techradar/software-news/~4/aKFaxevwe5Y
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...