Kaspersky catches hacker-for
Full article684 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The market is driven by cash-flush organizations that don’t want a malicious campaign traced back to them.
The hack-for-hire business is thriving.
Following the revelation in November that a new mercenary group had targeted organizations in South Asia, researchers on Thursday outlined how another suspected hack-for-hire shop has used malicious code to try to breach organizations in Europe and the Americas. It’s the latest innovation in a bustling market for buying access to government and corporate networks in a range of industries.
The new code, uncovered by analysts at security firm Kaspersky, can be used to remotely take over victim devices, and it interacts with the attackers via a communications-concealing protocol. The group responsible for the malware, known theatrically as DeathStalker, has been around for at least eight years but has only drawn public scrutiny in recent months, according to Kaspersky. And researchers have more digging to do.
“PowerPepper,” as the new malware is known, “is already the fourth malware strain affiliated with the actor, and we have discovered a potential fifth strain,” said Kaspersky’s Pierre Delcher. The hacking tool is called PowerPepper because the malicious code is delivered via an image of what appears to be a picture of a fern or peppers, a technique known as steganography. The hacking group used one-off social network accounts and VPN services to cover their tracks, Delcher said.
The DeathStalker mercenaries have previously tried to breach law and consultancy firms, Delcher said. But the researchers seem to know much more about the group’s malware than who is behind it. They did not say where the hackers are based or who has enlisted their services.
“We could not precisely identify most of the targets we discovered for PowerPepper,” Delcher said in an email. “Some decoy contents that have been leveraged during infections show a possible targeting of industrial organizations in Mexico and Turkey, and organizations in the UK.”
The latest maneuverings of DeathStalker follow a report in November from BlackBerry on another hack-for-hire group, dubbed CostaRicto, that was using custom malware to try to break into organizations in Bangladesh, India and several other countries.
Whether the intrusion attempts in this case have been successful remains unclear. But the attackers are giving themselves a chance for success by sending spearphishing emails with themes as varied as carbon emission regulations, the coronavirus and travel, depending on the target’s interest.
The hack-for-hire market is driven by cash-flush organizations that don’t want a malicious campaign traced back to them. The hacking mercenaries’ clients are hard to identify, but the targets often suggest government involvement. Another hack-for-hire group known as Bahamut has targeted Pakistani military officials, Sikh separatists in India and Indian business executives, according to a Reuters investigation.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/powerpepper-kaspersky-death-stalker-hack-for-hire/