{"id":8897,"date":"2015-05-15T14:35:23","date_gmt":"2015-05-15T06:35:23","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=8897"},"modified":"2015-05-15T20:36:46","modified_gmt":"2015-05-15T12:36:46","slug":"ph-govt-agencies-among-targets-of-chinese-speaking-cyberspies","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2015\/05\/15\/ph-govt-agencies-among-targets-of-chinese-speaking-cyberspies\/","title":{"rendered":"PH gov&#8217;t agencies among targets of Chinese-speaking cyberspies"},"content":{"rendered":"<p><span style=\"line-height: normal;\">From setting up spying infrastructure within a country\u2019s borders for real-time connections and data mining, to spying tools with 48 commands, a new report by Kaspersky Lab shows how the threat actor Naikon has spent the last five years successfully infiltrating national organizations around the South China Sea.<\/span><\/p>\n<p><span style=\"line-height: normal;\">Experts have discovered that Naikon attackers appear to be Chinese-speaking and that their primary targets are top-level government agencies and civil and military organizations in countries such as the Philippines, Malaysia, Cambodia, Indonesia, Vietnam, Myanmar, Singapore, and Nepal. &nbsp;&nbsp;<\/span><br \/>\n<span style=\"line-height: normal;\">Kaspersky Lab has identified the following hallmarks of Naikon operations:<\/span><\/p>\n<ul>\n<li><span style=\"line-height: normal;\">Each target country has a designated human operator, whose job it is to take advantage of cultural aspects of the country, such as a tendency to use personal email accounts for work;<\/span><\/li>\n<li><span style=\"line-height: normal;\">The placing of infrastructure (a proxy server) within the country\u2019s borders to provide daily support for real-time connections and data exfiltration;<\/span><\/li>\n<li><span style=\"line-height: normal;\">At least five years of high volume, high profile, &nbsp;geo-political attack activity;<\/span><\/li>\n<li><span style=\"line-height: normal;\">Platform-independent code, and the ability to intercept the entire network traffic;<\/span><\/li>\n<li><span style=\"line-height: normal;\">48 commands in the repertoire of the remote administration utility, including commands for taking a complete inventory, downloading and uploading data, installing add-on modules, or working with the command line.<\/span><\/li>\n<\/ul>\n<p><span style=\"line-height: normal;\">The Naikon cyberespionage threat actor was first mentioned by Kaspersky Lab in its recent report, \u201cThe Chronicles of the Hellsing &nbsp;APT: the Empire Strikes Back\u201d where the actor played a pivotal role in what turned out to be a unique story about payback in the world of advanced persistent threats. Hellsing is another threat actor who decided to take revenge when hit by Naikon.<\/span><\/p>\n<p><span style=\"line-height: normal;\">\u201cThe criminals behind the Naikon attacks managed to devise a very flexible infrastructure that can be set up in any target country, with information tunneling from victim systems to the command center. If the attackers then decide to hunt down another target in another country, they could simply set up a new connection. Having dedicated operators focused on their own particular set of targets also makes things easy for the Naikon espionage group,\u201d said Kurt Baumgartner, Principal Security Researcher, the GReAT at Kaspersky Lab.<\/span><\/p>\n<p><span style=\"line-height: normal;\">Naikon\u2019s targets are hit using traditional spear-phishing techniques, with emails carrying attachments designed to be of interest to the potential victim. This attachment might look like a Word document, but is in fact an executable file with a double extension.<\/span><br \/>\n&nbsp;<a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/05\/IMG_3903.png\"><img decoding=\"async\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/05\/IMG_3903.png\" alt=\"\"><\/a>&nbsp;<span style=\"line-height: normal;\"><br \/>\n<\/span><\/p>\n<p><span style=\"line-height: normal;\">Kaspersky Lab advises organizations to protect themselves against Naikon as follows:<\/span><\/p>\n<ul>\n<li><span style=\"line-height: normal;\">Don\u2019t open attachments and links from people you don\u2019t know<\/span><\/li>\n<li><span style=\"line-height: normal;\">Use an advanced anti-malware solution<\/span><\/li>\n<li><span style=\"line-height: normal;\">If you are unsure about the attachment, try to open it in a sandbox<\/span><\/li>\n<li><span style=\"line-height: normal;\">Make sure you have an up-to-date version of your operating system with all patches installed<\/span><\/li>\n<\/ul>\n<p><span style=\"line-height: normal;\">Kaspersky Lab protects users against the threat, using Automatic Exploit Prevention functionality to detect Naikon\u2019s components as: Exploit.MSWord.CVE-2012-0158, Exploit.MSWord.Agent, Backdoor.Win32.MsnMM, Trojan.Win32.Agent and Backdoor.Win32.Agent.<\/span><br \/>\n<span style=\"line-height: normal;\"><br \/>\n<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>From setting up spying infrastructure within a country\u2019s borders for real-time connections and data mining, to spying tools with 48 commands, a new report by Kaspersky Lab shows how the threat actor Naikon has spent the last five years successfully infiltrating national organizations around the South China Sea. Experts have discovered that Naikon attackers appear [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495,117],"class_list":["post-8897","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/8897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=8897"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/8897\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/8896"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=8897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=8897"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=8897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}