New report unearths the expertise in Russian hackers' code
Full article574 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Hackers from an advanced persistent threat group linked to Russian intelligence recently created a malware tool that takes advantage of a bug in a popular security program — illustrating the care that professional hackers take to evade detection.
Hackers from an advanced persistent threat group linked to Russian intelligence recently created a malware tool that takes advantage of a bug in a popular security program — illustrating the care that professional hackers take to evade detection.
In a blog post Friday, researchers from cybersecurity company Palo Alto Networks said they last month found a “dropper” — malicious code hidden in an email attachment which installs itself on a victim’s machine — that was undetectable by IDA, or Interactive DisAssembler.
IDA is an industry-standard tool that shows the instructions actually executed by a computer’s processor — enabling security researchers to detect and analyze deployed malware.
It’s used by “Virtually all anti-virus companies, most vulnerability research companies, many of the large software development companies and, above everything else, three letter agencies and military organizations,” according to IDA’s maker — Belgium based Hex-Rays SA.
The researchers said the dropper was a tool deployed by the APT group linked to the Democratic National Committee hack this year — variously known as Cozy Bear, APT 29 or Dukes. The group has previously targeted the unclassified computer networks of the White House, State Department, and U.S. Joint Chiefs of Staff.
Significantly, the dropper, sent on Aug. 10, concealed itself from IDA by taking advantage of a bug that Hex-Rays had found and fixed. The notice about the IDA update — noting the bug as fixed in the latest release — was distributed Aug. 8.
The threat group, conclude the researchers, “knows that malware analysts tasked with reverse engineering their tools typically use the IDA disassembler.”
The speed with which Cozy Bear were able to deliver malware that exploited the IDA bug speaks to the professionalism of their coders and the care which they take to avoid detection and analysis.
“It appears this group looks for ways to evade [security software], specifically in this case by monitoring release notes from known malware analysis tools to deploy their own countermeasures,” the researchers conclude.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/new-report-unearths-expertise-russian-hackers-code/