{"id":31643,"date":"2018-04-16T11:31:41","date_gmt":"2018-04-16T03:31:41","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=31643"},"modified":"2018-04-16T11:31:41","modified_gmt":"2018-04-16T03:31:41","slug":"asia-and-middle-east-a-hotbed-of-new-threat-actors-in-q1-2018","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/04\/16\/asia-and-middle-east-a-hotbed-of-new-threat-actors-in-q1-2018\/","title":{"rendered":"Asia and Middle East a hotbed of new threat actors in Q1 2018"},"content":{"rendered":"<p dir=\"ltr\"><strong>During the first three months of the year, Kaspersky Lab researchers discovered a wave of new APT activity based mainly in Asia \u2013 more than 30% of Q1 reports were dedicated to threat operations in this region. A peak of activity was also observed in the Middle East with a number of new techniques used by actors. These and other trends are covered in Kaspersky Lab\u2019s latest quarterly threat intelligence summary.<\/strong><\/p>\n<p dir=\"ltr\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-29693\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity.jpg\" alt=\"\" width=\"642\" height=\"480\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity.jpg 642w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity-300x224.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity-102x75.jpg 102w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity-600x450.jpg 600w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity-210x158.jpg 210w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/09\/cybersecurity-390x293.jpg 390w\" sizes=\"auto, (max-width: 642px) 100vw, 642px\" \/><\/a><\/p>\n<p dir=\"ltr\">In the first quarter of 2018, Kaspersky Lab researchers continued to detect cyber activities by advanced persistent threat (APT) groups speaking languages including Russian, Chinese, English and Korean, among others. And while some well-known actors didn\u2019t show any noteworthy activity, a rising number of APT operations and new threat actors were detected in the Asian region. This rise is explained in part by the <a href=\"https:\/\/securelist.com\/olympicdestroyer-is-here-to-trick-the-industry\/84295\/\" target=\"_blank\" rel=\"nofollow noopener\">Olympic Destroyer<\/a> malware attack on the Pyeongchang Olympic Games.<\/p>\n<p dir=\"ltr\">Highlights in Q1, 2018 include:<\/p>\n<ul>\n<li dir=\"ltr\">Continuous rise of Chinese-speaking activity, including the ShaggyPanther cluster of activity targeting government entities mainly in Taiwan and Malaysia, and CardinalLizard, which in 2018 increased its interest in Malaysia alongside an existing focus on the Philippines, Russia, and Mongolia.<\/li>\n<li dir=\"ltr\">Recorded APT activity in South Asia. Pakistan military entities have been under attack from the newly discovered Sidewinder group.<\/li>\n<li dir=\"ltr\">IronHusky APT apparently stops targeting Russian military actors and transfers all its efforts to Mongolia. At the end of January 2018, this Chinese-speaking actor launched an attack campaign on Mongolian government organizations before their meeting with the International Monetary Fund (IMF).<\/li>\n<li dir=\"ltr\"><span id=\"yiv1941490352gmail-84\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_84 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-93\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_93 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-94\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_94 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-90\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_90 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-182\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_182 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-160\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_160 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-152\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_152 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\"><span id=\"yiv1941490352gmail-91\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_91 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_gramm yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-Grammar yiv1941490352gmail-only-ins yiv1941490352gmail-replaceWithoutSep\">Korean<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span> peninsula remains in focus. The Kimsuky APT, targeting South Korean think tanks and political activities, has renewed its arsenal with a completely new framework designed for cyberespionage and used in a spear-phishing campaign. Furthermore, a subset of the infamous Lazarus group, Bluenoroff, has shifted to new targets including cryptocurrency companies and Point of Sales (PoS).<\/li>\n<\/ul>\n<p dir=\"ltr\">Kaspersky Lab also detected a peak of threat activity in the Middle East. For example, the StrongPity APT launched a number of new Man-in-the-Middle (<span id=\"yiv1941490352gmail-72\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_72 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\"><span id=\"yiv1941490352gmail-81\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_81 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\"><span id=\"yiv1941490352gmail-84\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_84 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\"><span id=\"yiv1941490352gmail-78\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_78 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\"><span id=\"yiv1941490352gmail-169\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_169 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\"><span id=\"yiv1941490352gmail-141\" class=\"yiv1941490352gmail-gr_ yiv1941490352gmail-gr_141 yiv1941490352gmail-gr-alert yiv1941490352gmail-gr_spell yiv1941490352gmail-gr_inline_cards yiv1941490352gmail-gr_run_anim yiv1941490352gmail-ContextualSpelling yiv1941490352gmail-ins-del yiv1941490352gmail-multiReplace\">MiTM<\/span><\/span><\/span><\/span><\/span><\/span>) attacks on internet service provider (ISP) networks. Another highly skilled cybercriminal group, the Desert Falcons, returned to target Android devices with malware previously used in 2014.<\/p>\n<p dir=\"ltr\">Also, in Q1, Kaspersky Lab researchers discovered several groups routinely targeting routers and networking hardware in their campaigns, an approach adopted years ago by actors such as Regin and CloudAtlas. According to experts, routers will continue to be a target for attackers as a way of getting a foothold in a victim\u00b4s infrastructure.<\/p>\n<p dir=\"ltr\">\u201cDuring the first three months of the year we saw a number of new threat groups of different levels of sophistication, but which, overall, were using the most common and available malware tools. At the same time, we observed no significant activity from some well-known actors. This leads us to believe that they are rethinking their strategies and reorganizing their teams for future attacks.\u201d said Vicente Diaz, Principal Security Researcher at Kaspersky Lab GReAT team.<\/p>\n<p dir=\"ltr\">The newly published Q1 APT Trends report summarizes the findings of Kaspersky Lab\u2019s subscriber-only threat intelligence reports. During the first quarter of 2018, Kaspersky Lab\u2019s Global Research and Analysis Team created 27 private reports for subscribers, with Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malware-hunting.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>During the first three months of the year, Kaspersky Lab researchers discovered a wave of new APT activity based mainly in Asia \u2013 more than 30% of Q1 reports were dedicated to threat operations in this region. A peak of activity was also observed in the Middle East with a number of new techniques used by actors. These and other trends are covered in Kaspersky Lab\u2019s latest quarterly threat intelligence summary.<\/p>\n","protected":false},"author":6,"featured_media":29693,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,25],"tags":[117,103,54],"class_list":["post-31643","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-software","tag-kaspersky-lab","tag-malware","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31643","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=31643"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31643\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/29693"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=31643"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=31643"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=31643"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}