[size=45]An internet gang targets legal and financial institutions and travel agencies with new malware
two hours ago[/size]
Kaspersky experts were able to identify a version with new functionality of the Janicab malware, which is used by the DeathStalker gang, which specializes in advanced persistent threats, to infiltrate specific organizations in several sectors. The new version was spotted in regions of Europe and the Middle East, and it was found to be exploiting some official web services, such as YouTube, as part of the infection chain.
Janicab infection can lead, for example, to targeted logistical and legal challenges, improving the standing of competitors, and unannounced audits that may reveal biases and abuses in the use of intellectual property, making its damages different from the traditional damages resulting from attacks such as digital extortion or ransom.
Janicab can be considered modular malware written in an interpreted language, which means that the attacker is able to add functionality or include files, or remove them, with little effort. And it was clear from Kaspersky's remote readings that the latest Janicab versions have witnessed significant changes in their structural structure, with archive copies containing many files written in Python, and other pieces used later in the hacking process. This is despite the fact that the delivery mechanism is still based on phishing. Once the victim is deceived and the malicious file is opened, a series of malicious files are sequentially downloaded onto the system.
One of the defining features of DeathStalker is its use of DDR services, or web services, to host an encrypted string that is later decrypted by a malware implant. According to a new report, Kaspersky was able to identify the use of old YouTube links that were present in intrusions that took place in 2021. The gang was able to operate undercover and repeatedly use its command-and-control architecture, given the difficulty of finding unlisted web links.
The affected enterprises that fell within DeathStalker's traditional domain included primarily legal, financial and investment firms. But Kaspersky also recorded activity targeting travel agencies. Europe and the Middle East were considered ideal areas of operation for the gang, but to varying degrees between the countries of the two regions.
Dr. Amin Hasebini, Head of the Research Center for the Middle East, Turkey and Africa in the global research and analysis team at Kaspersky, said that it can be safely assumed that the main objectives of the DeathStalker gang are to steal confidential information related to legal disputes related to VIPs and large financial assets, as well as commercial information that affects competitiveness, and information about mergers and acquisitions; This is given that legal and financial institutions are “a common target for this gang.” He added, "Organizations operating in these sectors must prepare for such breaches and update their threat models to ensure that data remains secure."
Affected organizations should rely on application whitelisting and operating system hardening as effective methods to prevent intrusive attempts. This is because the gang continues to use interpreted language-based malware such as Python, VBE, and VBS in recent hacking attempts. Security agencies should also look for Internet Explorer browser actions that operate without a user interface, since Janicab uses the browser in stealth mode to communicate with the command-and-control infrastructure.
[You must be registered and logged in to see this link.]
two hours ago[/size]
[You must be registered and logged in to see this image.]
Kaspersky experts were able to identify a version with new functionality of the Janicab malware, which is used by the DeathStalker gang, which specializes in advanced persistent threats, to infiltrate specific organizations in several sectors. The new version was spotted in regions of Europe and the Middle East, and it was found to be exploiting some official web services, such as YouTube, as part of the infection chain.
Janicab infection can lead, for example, to targeted logistical and legal challenges, improving the standing of competitors, and unannounced audits that may reveal biases and abuses in the use of intellectual property, making its damages different from the traditional damages resulting from attacks such as digital extortion or ransom.
Janicab can be considered modular malware written in an interpreted language, which means that the attacker is able to add functionality or include files, or remove them, with little effort. And it was clear from Kaspersky's remote readings that the latest Janicab versions have witnessed significant changes in their structural structure, with archive copies containing many files written in Python, and other pieces used later in the hacking process. This is despite the fact that the delivery mechanism is still based on phishing. Once the victim is deceived and the malicious file is opened, a series of malicious files are sequentially downloaded onto the system.
One of the defining features of DeathStalker is its use of DDR services, or web services, to host an encrypted string that is later decrypted by a malware implant. According to a new report, Kaspersky was able to identify the use of old YouTube links that were present in intrusions that took place in 2021. The gang was able to operate undercover and repeatedly use its command-and-control architecture, given the difficulty of finding unlisted web links.
- Unlisted YouTube DDR sample used in recent hacks
The affected enterprises that fell within DeathStalker's traditional domain included primarily legal, financial and investment firms. But Kaspersky also recorded activity targeting travel agencies. Europe and the Middle East were considered ideal areas of operation for the gang, but to varying degrees between the countries of the two regions.
Dr. Amin Hasebini, Head of the Research Center for the Middle East, Turkey and Africa in the global research and analysis team at Kaspersky, said that it can be safely assumed that the main objectives of the DeathStalker gang are to steal confidential information related to legal disputes related to VIPs and large financial assets, as well as commercial information that affects competitiveness, and information about mergers and acquisitions; This is given that legal and financial institutions are “a common target for this gang.” He added, "Organizations operating in these sectors must prepare for such breaches and update their threat models to ensure that data remains secure."
Affected organizations should rely on application whitelisting and operating system hardening as effective methods to prevent intrusive attempts. This is because the gang continues to use interpreted language-based malware such as Python, VBE, and VBS in recent hacking attempts. Security agencies should also look for Internet Explorer browser actions that operate without a user interface, since Janicab uses the browser in stealth mode to communicate with the command-and-control infrastructure.
[You must be registered and logged in to see this link.]
Today at 1:56 pm by Rocky
» MM&C 7/4/24 Tabaqchali: An Unfolding Structural Economic Transformation in Iraq
Today at 12:15 pm by Rocky
» utube 7/4/24 MM&C IQD Updates - Iraqi Dinar - Relations w / Baghdad & Kurdistan - Good - Financial
Today at 7:25 am by Rocky
» utube 7/2/24 MM&C IQD Update Part 2 - Iraqi Dinar - Automation for Revenues - Singapore Agreement
Today at 7:23 am by Rocky
» utube 7/2/24 MM&C part 1 Iraqi DinarPart 1 - IQD Update - Progession of Intergr
Today at 7:21 am by Rocky
» MM&C 7/2/24 The dollar in the parallel market.. Al-Sudani’s advisor presents a different vision and
Today at 7:20 am by Rocky
» Al-Sudani: Iraq's growth rate is the highest in the region and we have made significant progress in
Today at 7:16 am by Rocky
» What terrified Barzani and prompted him to visit Baghdad?
Today at 7:12 am by Rocky
» Barzani to ambassadors of 8 countries: Taking into consideration the interest of Iraq and the region
Today at 7:10 am by Rocky
» Trade participates in the preparatory meeting of the Iraqi-Jordanian Committee
Today at 7:06 am by Rocky
» The most prominent of which is the decision of the Central Bank.. Three reasons behind the rise of t
Today at 7:02 am by Rocky
» Baghdad buildings.. apartments rising quickly and prices soaring even higher
Today at 7:00 am by Rocky
» Al-Sudani stresses the importance of the public sector's role in implementing government priorities
Today at 6:58 am by Rocky
» Today.. Central Bank sales record more than 280 million dollars
Today at 6:55 am by Rocky
» Parliamentary movement to cancel decisions of the dissolved Revolutionary Command Council
Today at 6:54 am by Rocky
» Sudanese advisor reveals the reason for the rise in the dollar price
Today at 6:53 am by Rocky
» The Slums Law is in the Government’s Halls and Parliament is Waiting for Its Arrival.. MP Speaks to
Today at 6:51 am by Rocky
» Oil confirms achieving advanced rates in gas investment
Today at 5:39 am by Rocky
» Economist: Increased demand for electricity prompts us to look for “urgent solutions” to generate po
Today at 5:37 am by Rocky
» When will you leave the country? ... Iraq demands and America procrastinates
Today at 5:36 am by Rocky
» Demand for Al-Sudani to reveal the results of the investigations into the assassination of Al-Nasr l
Today at 5:35 am by Rocky
» Parliamentary Committee: The Ministry of Education’s budget is small and does not live up to the lev
Today at 5:34 am by Rocky
» Iraq announces drilling and reclaiming 105 oil wells during the first half of the year
Today at 5:32 am by Rocky
» For the fourth day.. Dollar prices continue to rise in Baghdad and Erbil
Today at 5:31 am by Rocky
» In the presence of Massoud Barzani .. Sunni forces hold a "decisive" meeting to resolve the crisis o
Today at 5:29 am by Rocky
» "Short-term".. Al-Sudani's advisor explains the reasons for the continued rise in the exchange rate
Today at 5:26 am by Rocky
» During 2024.. Petroleum Products Counts Gas Fuel Consumption Quantities for Cars
Today at 5:25 am by Rocky
» Iran, Turkmenistan officially sign gas swap agreement to supply to Iraq
Today at 5:24 am by Rocky
» Parliamentary Committee Identifies a “Fundamental Problem” Facing the Oil and Gas Law.. How Can It B
Today at 5:23 am by Rocky
» "We have not chosen the company to implement the project yet." Baghdad Municipality reveals the late
Today at 5:22 am by Rocky
» Iraq is the third country in which Türkiye has implemented the most projects in half a century
Today at 5:21 am by Rocky
» Iraq decides to introduce artificial intelligence in this field
Today at 5:20 am by Rocky
» Plan to convert oil refineries to environmentally friendly
Today at 5:19 am by Rocky
» Baghdad Airport Expansion to 9 Million Passengers Annually
Today at 5:18 am by Rocky
» Basra pursues land contract fraud
Today at 5:17 am by Rocky
» Government policy to control the state's public finances
Today at 5:15 am by Rocky
» Advisor: Iraq aspires to lead the Fourth Industrial Revolution
Today at 5:14 am by Rocky
» Baghdad Council threatens to confiscate illegal generators
Today at 5:13 am by Rocky
» Iraqi Creatives Museums and Cultural Centers
Today at 5:12 am by Rocky
» Oil: Gas investment reached 62%
Today at 5:11 am by Rocky
» Barzani in Baghdad
Today at 5:10 am by Rocky
» World Bank: Iraq is among the middle-income countries
Today at 5:09 am by Rocky
» Experts praise agricultural policies and call for supporting farmers
Today at 5:08 am by Rocky
» The Ministry of Interior issues ID cards to owners of "positive content"
Today at 5:05 am by Rocky
» Minister of Labor: Anbar's share of police contracts is 2,377 beneficiaries
Today at 5:04 am by Rocky
» The Minister of Labor holds social researchers morally responsible and assigns them two basic tasks
Today at 5:03 am by Rocky
» Kurdistan Finance announces the start of distributing salaries for these categories next Sunday
Today at 5:02 am by Rocky
» Judge Zidane visits the Supreme and Constitutional Courts of Azerbaijan
Today at 5:00 am by Rocky
» Coordination Framework: The coming days will witness the "birth" of the Diyala local government
Today at 4:59 am by Rocky
» An economist explains the reasons for the dollar’s rise and sets a condition for its decline - Urg
Today at 4:58 am by Rocky
» Investment Authority announces the processing of 249 stalled projects
Today at 4:56 am by Rocky
» Final statement of the meeting of the General Secretariat of the Union, June 29-30, 2024.. Baghdad S
Today at 4:55 am by Rocky
» Chief Justice describes President Barzani’s visit to Baghdad as “important and historic”
Today at 4:54 am by Rocky
» Masrour Barzani welcomes the Federal Court’s decision: It will strengthen confidence in the relation
Today at 4:53 am by Rocky
» Kurdistan Council of Ministers discusses equalizing the salaries of retirees in the region with thei
Today at 4:52 am by Rocky
» President Barzani after meeting with Al-Sudani: We had a constructive dialogue and will continue coo
Today at 4:50 am by Rocky
» Al-Sudani's financial advisor reveals the reason for the continued rise of the dollar and confirms:
Today at 4:49 am by Rocky
» Barzani reveals the goals of his visit to Baghdad: There is an intention to resolve the differences
Today at 4:48 am by Rocky
» The Turkish army penetrates into Iraqi territory with Baghdad's approval!
Today at 4:47 am by Rocky
» The Regional Council of Ministers discusses unifying the salaries of its retirees with the center
Today at 4:46 am by Rocky
» Two countries sign a contract on gas supplied to Iraq
Today at 4:45 am by Rocky
» Communications: Cable contracts will improve internet service in Iraq
Today at 4:44 am by Rocky
» Interior Ministry reveals two “strategies” regarding social media
Today at 4:43 am by Rocky
» Will social security guarantee the rights of workers and earners? An economist answers
Today at 4:42 am by Rocky
» Al-Sudani receives a group of sheikhs and dignitaries of the Zubaa tribe in Baghdad
Today at 4:41 am by Rocky
» Discussing the file of the international coalition and the presidency of parliament.. Details of the
Today at 4:39 am by Rocky
» Experts: Coordination between the center and the region is necessary to find a solution to the Turki
Today at 4:38 am by Rocky
» Problems still exist.. Government expects camps to close a month after the scheduled date
Today at 4:37 am by Rocky
» The dollar soars in Baghdad markets, exceeding the 149 barrier
Today at 4:35 am by Rocky
» Iraqi graduation research included in international databases
Today at 4:34 am by Rocky
» Compliance or arrest.. Baghdad Council issues final warning to private generator owners
Today at 4:32 am by Rocky
» With water scarcity, desertification is growing in Iraq!
Today at 4:31 am by Rocky
» With the increasing demand for it.. Petroleum Products opens 3 new outlets for LPG
Today at 4:30 am by Rocky
» Generator owners in Baghdad violate government decisions and raise prices!
Today at 4:29 am by Rocky
» Barzani and Mandalawi discuss the issue of electing the Speaker of Parliament
Today at 4:27 am by Rocky
» Despite the rise in the dollar, Saleh: The parallel market today is not important
Yesterday at 5:53 pm by Rocky
» Securities Commission: The government has successfully completed the sale of financial bonds
Yesterday at 5:47 pm by Rocky
» Ankara: We are working with Iraq to develop a plan to deal with the water file and eliminate all cha
Yesterday at 5:46 pm by Rocky
» Minister of Communications: Cable contracts will improve internet service in Iraq
Yesterday at 5:44 pm by Rocky
» Iraq reinforces its borders with Syria with 13 additional military regiments
Yesterday at 5:39 pm by Rocky
» Kurdistan responds to a letter from the Federal Court about localizing its employees’ salaries
Yesterday at 5:37 pm by Rocky
» Parliamentary Finance: The remaining months are not enough to disburse budget funds
Yesterday at 5:36 pm by Rocky
» Investment Authority announces the processing of 249 stalled projects
Yesterday at 5:35 pm by Rocky
» Today.. The Central Bank sells only about 15 million dollars domestically
Yesterday at 5:32 pm by Rocky
» Rafidain Bank announces completion of 3288 loan transactions for projects and real estate during the
Yesterday at 7:07 am by Rocky
» Israel fabricates justifications for attacks on Iraq
Yesterday at 7:05 am by Rocky
» Tribal Conflicts: When Laws Are Silent and Guns Speak
Yesterday at 7:04 am by Rocky
» Obelisk Hour: Will the Kurdistan Region Turn into “Southern Türkiye” Instead of “Northern Iraq”?
Yesterday at 7:03 am by Rocky
» Al-Sudani to Barzani: We have made significant progress in building trust between the central and re
Yesterday at 7:02 am by Rocky
» National Security at Stake: $670 Million Defense Contract with Corrupt Thales
Yesterday at 7:00 am by Rocky
» Barzani discusses in Baghdad common files with the State Administration Alliance
Yesterday at 6:59 am by Rocky
» Al-Halbousi's ambition to be the "Barzani of Anbar" clashes with the rejection of the people of his
Yesterday at 6:56 am by Rocky
» More than $260 million in foreign transfers to the Central Bank of Iraq in today's auction
Yesterday at 6:54 am by Rocky
» Al-Sudani's advisor explains: Has the government adopted a new approach to activate the private sect
Yesterday at 6:53 am by Rocky
» Al-Sudani: We have overcome the inherited problems with the Kurdistan Region
Yesterday at 6:50 am by Rocky
» Parliamentary Culture confirms its determination to legislate the Right to Access Information Law in
Yesterday at 6:48 am by Rocky
» The President of the Supreme Judicial Council receives the President of the Bar Association to discu
Yesterday at 6:46 am by Rocky
» Parliamentary confirmation to encourage Finnish companies to work in Iraq
Yesterday at 6:45 am by Rocky
» Ministry of Planning: A government delegation is holding negotiations in Berlin with the German side
Yesterday at 6:43 am by Rocky