{"id":27864,"date":"2017-03-01T15:14:43","date_gmt":"2017-03-01T07:14:43","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=27864"},"modified":"2017-03-01T15:14:43","modified_gmt":"2017-03-01T07:14:43","slug":"adwind-switches-to-business-used-against-targets-in-over-100-countries-and-territories","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/03\/01\/adwind-switches-to-business-used-against-targets-in-over-100-countries-and-territories\/","title":{"rendered":"Adwind switches to business, used against targets in over 100 countries and territories"},"content":{"rendered":"<p><strong>Kaspersky Lab announced that it\u00a0detected a massive new hit by the Adwind Remote Access Tool (RAT). This multifunctional backdoor has been used in attacks against more than 1,500 organizations in over 100 countries and territories including the Philippines.<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-27865\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind.jpg\" alt=\"\" width=\"665\" height=\"666\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind.jpg 665w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind-150x150.jpg 150w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind-300x300.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Adwind-50x50.jpg 50w\" sizes=\"auto, (max-width: 665px) 100vw, 665px\" \/><\/a><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53682\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53681\">The attacks have impacted various industrial sectors, including retail and distribution (20.1%), architecture and construction (9.5%), shipping and logistics (5.5%), insurance and legal services (5%) and consulting (5%).<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53688\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53690\">Adwind\u2019s victims receive e-mails sent in the name of the HSBC Advising Service (from the <a href=\"http:\/\/mail.hsbcnet.hsbc.com\/\" target=\"_blank\" rel=\"nofollow\">mail.hsbcnet.hsbc.com<\/a> domain), with payment advice in the attachment. According to Kaspersky Lab research, the activity of this email domain can be tracked back to 2013.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53693\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53692\">Instead of instructions, the attachments contain the malware sample. If the targeted user opens the attached ZIP file, which has a JAR file in it, the malware self-installs and attempts to communicate with its command and control server. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53697\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53696\">The malware allows the attacker to gain almost complete control over the compromised device and steal confidential information from the infected computer.<\/span><\/p>\n<p dir=\"ltr\">The geographical distribution of attacked users registered by the Kaspersky Security Network (KSN) during this period shows that almost half of them (more than 40%) were living in the following ten countries:<\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53709\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53711\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/lh6.googleusercontent.com\/SxKKY8gU4RACeQlpY7WCySOanz68yRLsNrL4pa6bELSQRIU6nW-T4gcTyslLjv85KJccU0oPWcqrfM0iWsuanBFOhC7EZMeUsOAzYEcoSyKhv55XB6cTMp5YxqMHTluEYv_LS79vaXRSV6d69w\" width=\"514\" height=\"295\" \/><\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53705\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53707\">According to Kaspersky Lab researchers, since the victims include a high proportion of businesses, criminals could use industry-specific mailing list to target their attacks. Considering the number of detections, they were focused on attack scale and outreach, rather than on sophisticated technology.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53700\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53703\"><img loading=\"lazy\" decoding=\"async\" id=\"yui_3_16_0_ym19_1_1488269393406_53702\" class=\"aligncenter\" src=\"https:\/\/lh4.googleusercontent.com\/xzVu8MLHEQ0ddBRpZbECiBRBYpe-50v93fq8C3zW89yaMSDXtquWSYuJhgOLLO32_y3M8tEO93bdiOtkL17rchECdPr6ouFVmzZOfzDIMkBxLiTQ5Dj-zudgWaeBOoXuhNbSYvJBPHdCwC3qjA\" width=\"564\" height=\"358\" \/><\/span><\/p>\n<p dir=\"ltr\">History of the Adwind RAT malware<\/p>\n<p dir=\"ltr\">In 2016, Kaspersky lab <a href=\"https:\/\/securelist.com\/blog\/research\/73660\/adwind-faq\/\" target=\"_blank\" rel=\"nofollow\">reported<\/a> attacks made with the Adwind Remote Access Tool (RAT), a cross-platform, multifunctional malware program also known as AlienSpy, Frutas, Unrecom, Sockrat, JSocket and jRat, which is distributed through a single malware-as-a-service platform.<\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53729\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53728\">One of the main features that distinguishes the Adwind RAT from other commercial malware is that it is distributed openly in the form of a paid service, where the \u201ccustomer\u201d pays a fee to use the malicious program. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53726\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53725\">According to the results of the investigation, which was conducted between 2013 and 2016, different versions of the Adwind malware have been used in attacks against at least 443,000 private users, commercial and non-commercial organizations around the world.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53723\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53722\">In order to protect yourself and your organization against this threat, Kaspersky Lab encourages enterprises to limit the use of Java to isolated applications that are impossible to run without the use of this platform. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53720\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53719\">In a similar way to financial operations, Java applications can be isolated with maximum security principles applied to them. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1488269393406_53717\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53716\">Kaspersky Lab\u2019s solutions offer a wide variety of Application Control features to set the granular policy, and monitor and control the use of specific applications on corporate endpoints.<\/span><\/p>\n<p dir=\"ltr\" style=\"text-align: center;\"><em><span id=\"yui_3_16_0_ym19_1_1488269393406_53735\">For a full\u00a0overview of financial threats and their evolution during the last year, read: &#8220;<\/span><a id=\"yui_3_16_0_ym19_1_1488269393406_53755\" href=\"https:\/\/securelist.com\/analysis\/publications\/77623\/financial-cyberthreats-in-2016\" target=\"_blank\" rel=\"nofollow\"><span id=\"yui_3_16_0_ym19_1_1488269393406_53754\">Financial Cyberthreats in 2016<\/span><\/a><span id=\"yui_3_16_0_ym19_1_1488269393406_53757\">\u201d. <\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab has detected a massive new hit by the Adwind Remote Access Tool (RAT). This multifunctional backdoor has been used in attacks against more than 1,500 organizations in over 100 countries and territories including the Philippines.<\/p>\n","protected":false},"author":6,"featured_media":27865,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[5128,101,103,54],"class_list":["post-27864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-adwind","tag-kaspersky","tag-malware","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=27864"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/27865"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=27864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=27864"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=27864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}