{"id":1740,"date":"2013-09-06T13:40:18","date_gmt":"2013-09-06T05:40:18","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=1740"},"modified":"2013-09-06T13:40:57","modified_gmt":"2013-09-06T05:40:57","slug":"nettraveler-is-back-with-new-tricks","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2013\/09\/06\/nettraveler-is-back-with-new-tricks\/","title":{"rendered":"NetTraveler is back with new tricks"},"content":{"rendered":"<p><strong>Kaspersky Lab researchers recently announced a new attack vector of NetTraveler, an advanced persistent threat that has already infected hundreds of high profile victims in more than 40 countries.<\/strong><\/p>\n<p>According to Kaspersky Lab, an advanced persistent threat (APT) refers to a highly precise sort of cyberattack. APT can also refer to groups, often state sponsored or well-funded in other ways, that are responsible for launching such precision attacks. The end-goal of an APT-style attack is to compromise a machine on which there is some sort of valuable information.<\/p>\n<p>Known targets of NetTraveler (also known as \u201cTravnet\u201d, \u201cNetfile\u201d or &#8220;Red Star&#8221; APT) include Tibetan\/Uyghur activists, oil industry companies, scientific research centers and institutes, universities, private companies, governments and governmental institutions, embassies and military contractors.<\/p>\n<p>Immediately after the public exposure of the NetTraveler operations in June 2013, the attackers shut down all known command and control systems and moved them to new servers in China, Hong Kong and Taiwan. They also continued the attacks unhindered, just like the current case shows.<\/p>\n<p>Over the last few days, several spear-phishing e-mails were sent to multiple Uyghur activists. The Java exploit used to distribute this new variant of the Red Star APT was only recently patched in June 2013 and has a much higher success rate. The earlier attacks have used Office exploits (CVE-2012-0158) that was patched by Microsoft last April.<\/p>\n<p>In addition to the use of spear-phishing e-mails, APT operators have adopted the watering hole technique (web redirections and drive-by downloads on rigged domains) to infect victims surfing the web.<\/p>\n<p>Over the last month, Kaspersky Lab intercepted and blocked a number of infection attempts from the \u201cwetstock[dot]org\u201d domain, which is a known site linked to previous NetTraveler attacks.<\/p>\n<p>These redirections appear to come from other Uyghur-related websites that were compromised and infected by the NetTraveler attackers.<\/p>\n<p>Kaspersky Lab\u2019s Global Research and Analysis Team (GReAT) experts predict that other recent exploits could be integrated and used against the group\u2019s targets.<\/p>\n<p>The company\u2019s experts offer the following\u00a0 recommendations on how to stay safe from such attacks:<\/p>\n<ul>\n<li>\u00a0\u00a0\u00a0 Update Java to the most recent version or, if you don\u2019t use Java, uninstall it.<\/li>\n<li>\u00a0\u00a0\u00a0 Update Microsoft Windows and Office to the latest versions.<\/li>\n<li>\u00a0\u00a0\u00a0 Update all other third party software, such as Adobe Reader.<\/li>\n<li>\u00a0\u00a0\u00a0 Use a secure browser such as Google Chrome, which has a faster development and patching cycle than Windows\u2019 default Internet Explorer.<\/li>\n<li>\u00a0\u00a0\u00a0 Be wary of clicking on links and opening attachments from unknown persons.<\/li>\n<\/ul>\n<p>\u201cSo far, we haven\u2019t observed the use of zero-day vulnerabilities with the NetTraveler group. To defend against those, although patches don\u2019t help, but technologies such as DefaultDeny and Automatic Exploit Prevention can be quite effective fighting advanced persistent threats,\u201d advised Costin Raiu, GReAT Director at Kaspersky Lab.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_Map-of-victims.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1741\" alt=\"KL_Nettraveler_Map of victims\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_Map-of-victims-1024x723.png\" width=\"640\" height=\"451\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_Map-of-victims-1024x723.png 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_Map-of-victims-300x212.png 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_Map-of-victims.png 1600w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_victims-by-industries.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1742\" alt=\"KL_Nettraveler_victims by industries\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_victims-by-industries.png\" width=\"877\" height=\"545\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_victims-by-industries.png 877w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/09\/KL_Nettraveler_victims-by-industries-300x186.png 300w\" sizes=\"auto, (max-width: 877px) 100vw, 877px\" \/><\/a><\/p>\n<div id=\"__tbSetup\"><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab researchers recently announced a new attack vector of NetTraveler, an advanced persistent threat that has already infected hundreds of high profile victims in more than 40 countries.<\/p>\n","protected":false},"author":6,"featured_media":1741,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,117],"class_list":["post-1740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/1740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=1740"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/1740\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/1741"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=1740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=1740"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=1740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}