ASE Labs
Welcome Guest. Please register or log in now. There are 1612 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login

Kaspersky Lab Identifies 'MiniDuke', a New Malicious Program Designed for Spying on Multiple Government Entities and Institutions Across The World

Poster: SySAdmin
Posted on February 28, 2013 at 7:49:01 AM
Kaspersky Lab Identifies 'MiniDuke', a New Malicious Program Designed for Spying on Multiple Government Entities and Institutions Across The World

ABINGDON, England, February 28, 2013 /PRNewswire/ --

         New threat actors combine sophisticated "Old School" malware writing skills
  with newly advanced exploits in Adobe Reader to collect geopolitical intelligence from

                                   high profile targets

    Today Kaspersky Lab's team of experts published a new research report that analysed a
series of security incidents involving the use of the recently discovered PDF exploit in
Adobe Reader (CVE-2013-6040) and a new, highly customised malicious program known as
MiniDuke. The MiniDuke backdoor was used to attack multiple government entities and
institutions worldwide during the past week. Kaspersky Lab's experts, in partnership with
CrySys Lab, analysed the attacks in detail and published their findings.

    According to Kaspersky Lab's analysis, a number of high profile targets have already
been compromised by the MiniDuke attacks, including government entities in Ukraine,
Belgium, Portugal, Romania, the Czech Republic and Ireland. In addition, a research
institute, two think tanks, and healthcare provider in the United States were also
compromised, as was a prominent research foundation in Hungary.

    "This is a very unusual cyberattack," said Eugene Kaspersky, Founder and CEO of
Kaspersky Lab. "I remember this style of malicious programming from the end of the 1990s
and the beginning of the 2000s. I wonder if these types of malware writers, who have been
in hibernation for more than a decade, have suddenly awoken and joined the sophisticated
group of threat actors active in the cyberworld. These elite, "old school" malware writers
were extremely effective in the past at creating highly complex viruses, and are now
combining these skills with the newly advanced sandbox-evading exploits to target
government entities or research institutions in several countries."

    "MiniDuke's highly customised backdoor was written in Assembler and is very small in
size, being only 20kb," added Kaspersky. The combination of experienced old school malware
writers using newly discovered exploits and clever social engineering to compromise high
profile targets is extremely dangerous."

    Kaspersky Lab's Primary Research Findings:

       
        - The MiniDuke attackers are still active at this time and have created
          malware as recently as February 20, 2013. To compromise victims, the attackers used
          extremely effective social engineering techniques, which involved sending malicious
          PDF documents to their targets. The PDFs were highly relevant - with well-crafted
          content that fabricated human rights seminar information (ASEM) and Ukraine's foreign
          policy and NATO membership plans. These malicious PDF files were rigged with exploits
          attacking Adobe Reader versions 9, 10, and 11, bypassing its sandbox. A toolkit was
          used to create these exploits and it appears to be the same toolkit that was used in
          the recent attack reported by FireEye. However, the exploits used in the MiniDuke
          attacks were for different purposes and had their own customised malware.

       
        - Once the system is exploited, a very small downloader is dropped onto the
          victim's disc that's only 20kb in size. This downloader is unique per system and
          contains a customised backdoor written in Assembler. When loaded at system boot, the
          downloader uses a set of mathematical calculations to determine the computer's unique
          fingerprint, and in turn uses this data to uniquely encrypt its communications later.
          It is also programmed to avoid analysis by a hardcoded set of tools in certain
          environments like VMware. If it finds any of these indicators it will run idle in the
          environment instead of moving to another stage and exposing more of its functionality
          by decrypting itself further; this indicates the malware writers know exactly what
          antivirus and IT security professionals are doing in order to analyse and identify
          malware.

       
        - If the target's system meets the pre-defined requirements, the malware
          will use Twitter (unbeknownst to the user) and start looking for specific tweets from
          pre-made accounts. These accounts were created by MiniDuke's Command and Control (C2)
          operators, and the tweets maintain specific tags labeling encrypted URLs for the
          backdoors. These URLs provide access to the C2s, which then provide potential commands
          and encrypted transfers of additional backdoors onto the system via GIF files.

       
        - Based on the analysis, it appears that MiniDuke's creators provide a
          dynamic backup system that also can fly under the radar. If Twitter isn't working or
          the accounts are down the malware can use Google Search to find the encrypted strings
          to the next C2. This model is flexible and enables the operators to constantly change
          how their backdoors retrieve further commands or malcode as needed.

       
        - Once the infected system locates the C2, it receives encrypted backdoors
          that are obfuscated within GIF files and disguised as pictures that appear on a
          victim's machine. Once they are downloaded to the machine they can download a larger
          backdoor that carries out several basic actions, such as copy file, move file, remove
          file, make directory, kill process, and, of course, download and execute new malware.

       
        - The malware backdoor connects to two servers, one in Panama and one in
          Turkey, to receive instructions from the attackers.

    Kaspersky Lab's system detects and neutralizes the MiniDuke malware, classified as
HEUR:Backdoor.Win32.MiniDuke.gen and Backdoor.Win32.Miniduke. Kaspersky Lab also detects
the exploits used in the PDF documents, classified as Exploit.JS.Pdfka.giy.

    About Kaspersky Lab

    Kaspersky Lab is the world's largest privately held vendor of endpoint protection
solutions. The company is ranked among the world's top four vendors of security solutions
for endpoint users*. Throughout its 15-year history Kaspersky Lab has remained an
innovator in IT security and provides effective digital security solutions for consumers,
SMBs and enterprises. The company currently operates in almost 200 countries and
territories across the globe, providing protection for over 300 million users worldwide.
Learn more at http://www.kaspersky.co.uk.

    * The company was rated fourth in the IDC rating Worldwide Endpoint Security Revenue
by Vendor, 2011. The rating was published in the IDC report "Worldwide Endpoint Security
2012-2016 Forecast and 2011 Vendor Shares (IDC #235930, July 2012). The report ranked
software vendors according to earnings from sales of endpoint security solutions in 2011.

    (c) 2013 Kaspersky Lab. The information contained herein is subject to change without
notice. The only warranties for Kaspersky Lab products and services are set forth in the
express warranty statements accompanying such products and services. Nothing herein should
be construed as constituting an additional warranty. Kaspersky Lab shall not be liable for
technical or editorial errors or omissions contained herein.

    Follow us on Twitter

    http://www.twitter.com/kasperskyuk

    Like us on Facebook

    http://www.facebook.com/Kaspersky

       
        Editorial contact:

        Berkeley PR
        Louise Mapp
        kasperskylab@berkeleypr.co.uk
        Telephone: +44(0)118-909-0909

        1650 Arlington Business Park
        RG7 4SA, Reading

        Kaspersky Lab UK
        Ruth Knowles
        Ruth.Knowles@kasperskylab.co.uk
        Telephone: +44(0)871-789-1633

        Milton Business Park
        OX14 4RY, Oxford

Kaspersky Lab
 
Print This Entry
Tags PR Press Release
Related Articles
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Kingston HyperX Cloud 2 Pro Gaming Headset Unboxing
  • Synology DS415+ Unboxing
  • D-Link DCS-5020L Wireless IP Pan/Tilt IP Camera
  • Actiontec WiFi Powerline Network Extender Kit Unboxing
  • Durovis Dive Unboxing
  • Bass Egg Verb Unboxing
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
Latest Articles
  • D-Link Exo AC2600 Smart Mesh Wi-Fi Router DIR-2660-US
  • HyperX Double Shot PBT Keys
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones
  • ScharkSpark Beginner Drones
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera
  • Contour Unimouse Wireless Ergonomic Mouse
  • HyperX Cloud Alpha Pro Gaming Headset
  • Linksys Wemo Smart Home Suite
  • Fully Jarvis Adjustable Standing Desk
Latest Topics
  • Hello
  • Welcome to the new server at ASE Labs
  • Evercool Royal NP-901 Notebook Cooler at ASE Labs
  • HyperX Double Shot PBT Keys at ASE Labs
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones at ASE Labs
  • ScharkSpark Beginner Drones at ASE Labs
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard at ASE Labs
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera at ASE Labs
  • Kingston SDX10V/128GB SDXC Memory at ASE Labs
  • What are you listening to now?
  • Antec Six Hundred v2 Gaming Case at HardwareLogic
  • Sans Digital TR5UTP 5-Bay RAID Tower at HardwareLogic
  • Crucial Ballistix Smart Tracer 6GB PC3-12800 BL3KIT25664ST1608OB at HardwareLogic
  • Cooler Master Storm Enforcer Mid-Tower Gaming Case at HardwareLogic
  • Arctic M571-L Gaming Laser Mouse at ASE Labs
  • Contour Unimouse Wireless Ergonomic Mouse at ASE Labs
Advertisement
Advertisement
Press Release
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • Fujifilm launches "instax SQUARE SQ6 Taylor Swift Edition", designed by instax global partner Taylor Swift
  • Huawei nova 3 With Best-in-class AI Capabilities Goes on Sale Today
  • Rand McNally Introduces Its Most Advanced Dashboard Camera
  • =?UTF-8?Q?My_Size_to_Showcase_Its_MySizeId=E2=84=A2_Mobil?= =?UTF-8?Q?e_Measurement_Technology_at_CurvyCon_NYC?=
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 16 (5 Cached)] [Rows: 292 Fetched: 245] [Page Generation time: 0.017932176589966]